
Cloud Vulnerability DB
A community-led vulnerabilities database
There is a CSRF (Cross-Site Request Forgery) vulnerability in MCMS that can add an administrator account via ms/basic/manager/save.do. The vulnerability was assigned CVE-2022-29647 and was disclosed on June 2, 2022 (CISA Bulletin).
The vulnerability exists due to missing CSRF token validation when adding administrator users in the MCMS backend. When adding a user, the application does not implement proper token verification or referrer checking, making it vulnerable to CSRF attacks (GitHub POC).
An attacker can exploit this vulnerability to secretly add administrator users by tricking an authenticated administrator into visiting a specially crafted webpage. This allows the attacker to gain unauthorized administrative access to the MCMS backend system (GitHub POC).
The application should implement proper CSRF protection mechanisms including CSRF tokens and referrer validation when processing administrator user creation requests (GitHub POC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."