Masa CMS是Masa CMS组织的一个数字体验平台。 Masa CMS 7.5.2及之前版本存在跨站请求伪造漏洞,该漏洞源于cTrash.empty函数未验证反CSRF令牌,可能导致攻击者诱导管理员提交伪造请求清空回收站并永久删除所有已删除内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40325 | Masa CMS CSRF in content restoration allows unauthorized restoration of deleted content | |
| CVE-2026-40332 | Masa CMS open redirect via improper handling of scheme-relative URLs | |
| CVE-2026-40326 | Masa CMS CSRF in site bundle creation allows unauthorized site data export | |
| CVE-2026-40174 | Masa CMS CSRF in user address management allows unauthorized address changes |
No comments yet