MuraCMS Cross-Site Request Forgery Vulnerability in Bundle Creation Allowing Data Exfiltration

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in MuraCMS versions through 10.1.10. This vulnerability resides in the bundle creation feature, specifically within the 'csettings.cfc' createBundle method. It allows unauthenticated attackers to manipulate administrators into creating and saving site bundles that contain sensitive information, which are then stored in publicly accessible directories. The exploitation of this vulnerability could lead to unauthorized access and download of confidential data, including user accounts, password hashes, form submissions, email lists, plugins, and site content, all without the administrator's knowledge.

Impact

Exploitation of this vulnerability could result in complete data exfiltration from MuraCMS installations, including sensitive user information and site content, without the knowledge of the administrator.

Remediation

Users are advised to update to MuraCMS version 10.1.11 or later, where this vulnerability has been addressed.

Added: Mar 18, 2026, 4:55 PM
Updated: Mar 18, 2026, 4:55 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.5
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.