CVE-2017-15639

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
19/10/2017
Last modified:
20/04/2025

Description

tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:getmura:mura_cms:*:*:*:*:*:*:*:* 6.1 (including)