CVE-2022-29647: CSRF
Published May 31, 2022
·Updated
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
Affected Software
1 affected component
Mingsoft MCMS=5.2.7
Event History
May 31, 2022
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
Description
Frequently Asked Questions
1
What is CVE-2022-29647?
CVE-2022-29647 is a CSRF vulnerability in MCMS 5.2.7 that allows an attacker to add an administrator account via ms/basic/manager/save.do.
2
What is the severity of CVE-2022-29647?
CVE-2022-29647 has a severity rating of 8.8 (high).
3
How can the CSRF vulnerability in MCMS 5.2.7 be exploited?
The CSRF vulnerability in MCMS 5.2.7 can be exploited by an attacker to add an administrator account via the ms/basic/manager/save.do endpoint.
4
What software versions are affected by CVE-2022-29647?
CVE-2022-29647 affects MCMS 5.2.7.
5
Is there a fix for CVE-2022-29647?
As of now, no specific fix or patch has been released for CVE-2022-29647. It is recommended to contact the vendor for further guidance.