Description
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
Remediation
References
https://gist.github.com/aaaahuia/f708c6c8a320e0f3afbb9247903c4670
Related Vulnerabilities
CVE-2021-27850 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2022-35961 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2022-41966 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-43428 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2021-29459 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web