CSRF Vulnerability in MCMS Product by Vendor
CVE-2022-29647
8.8HIGH
What is CVE-2022-29647?
A CSRF vulnerability was found in MCMS version 5.2.7 that enables attackers to forge requests, resulting in unauthorized access to create an administrator account. This flaw can be exploited by sending specially crafted requests to the vulnerable endpoint ms/basic/manager/save.do, raising serious security concerns for web application integrity.
