CVE-2022-47002: Critical severity tina tinacms vulnerability
Published Feb 1, 2023
·Updated
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
Affected Software
6 affected components
MasaCMS MasaCMS<7.2.5
MasaCMS MasaCMS>=7.3<7.3.10
MasaCMS MasaCMS=7.4.0-alpha1
MasaCMS MasaCMS=7.4.0-alpha2
MasaCMS MasaCMS=7.4.0-beta1
MasaCMS MasaCMS=7.4.0-beta2
Remediation
Event History
Feb 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-47002?
CVE-2022-47002 is a vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta that allows attackers to bypass authentication via a crafted web request.
2
How severe is CVE-2022-47002?
CVE-2022-47002 has a severity rating of 9.8 (critical).
3
How can an attacker exploit CVE-2022-47002?
An attacker can exploit CVE-2022-47002 by sending a crafted web request to bypass authentication in the Remember Me function of Masa CMS.
4
Which versions of Masa CMS are affected by CVE-2022-47002?
Versions 7.2, 7.3, and 7.4-beta of Masa CMS are affected by CVE-2022-47002.
5
How can I fix CVE-2022-47002?
To fix CVE-2022-47002, it is recommended to update Masa CMS to version 7.3.10 or higher.