CVE-2022-27340: CSRF
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27340?
CVE-2022-27340 is a Cross-Site Request Forgery (CSRF) vulnerability in MCMS v5.2.7 that allows attackers to escalate privileges and modify data.
What is the severity of CVE-2022-27340?
CVE-2022-27340 has a severity value of 8.8 (high).
How does CVE-2022-27340 affect MCMS v5.2.7?
CVE-2022-27340 affects MCMS v5.2.7 by enabling attackers to perform Cross-Site Request Forgery (CSRF) attacks via /role/saveOrUpdateRole.do.
How can CVE-2022-27340 be exploited?
CVE-2022-27340 can be exploited by sending a specially crafted request to /role/saveOrUpdateRole.do to escalate privileges and modify data.
How to fix CVE-2022-27340?
To fix CVE-2022-27340, it is recommended to upgrade to a version of MCMS that is not affected by this vulnerability.