Vulnerabilities > CVE-2017-15639 - XXE vulnerability in Getmura Mura CMS 6.1

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
getmura
CWE-611
exploit available

Summary

tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.

Vulnerable Configurations

Part Description Count
Application
Getmura
1

Exploit-Db

descriptionMura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection. CVE-2017-15639. Webapps exploit for CFM platform
fileexploits/cfm/webapps/43045.txt
idEDB-ID:43045
last seen2017-10-25
modified2017-10-24
platformcfm
port
published2017-10-24
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43045/
titleMura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/144764/muracms-ssrfxxe.txt
idPACKETSTORM:144764
last seen2017-10-27
published2017-10-26
reporterAnthony Cole
sourcehttps://packetstormsecurity.com/files/144764/Mura-CMS-Server-Side-Request-Forgery-XXE-Injection.html
titleMura CMS Server-Side Request Forgery / XXE Injection