6.5
CVSSv3

CVE-2017-15639

Published: 19/10/2017 Updated: 08/11/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

tasks/feed/readRSS.cfm in Mura CMS prior to 6.2 allows malicious users to bypass intended access restrictions by leveraging the "draggable feeds" feature.

Vulnerable Product Search on Vulmon Subscribe to Product

getmura mura cms

Exploits

# Exploit Title: Mura CMS before 62 SSRF + XXE # Date: 30-10-2017 # Exploit Author: Anthony Cole # Vendor Homepage: wwwgetmuracom/ # Version: before 62 # Contact: twittercom/acole76 # Website: twittercom/acole76 # Tested on: Windows 2008 w/ Coldfusion 8 # CVE: CVE-2017-15639 # Category: webapps 1 Description Any us ...
Mura CMS versions prior to 62 suffer from server-side request forgery and XML external entity injection vulnerabilities ...