CVE-2022-29647
Description
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
MCMS 5.2.7 has a CSRF vulnerability that allows an attacker to add an administrator account via the /ms/basic/manager/save.do endpoint.
Vulnerability
MCMS version 5.2.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in the background user addition functionality. The /ms/basic/manager/save.do endpoint does not include a CSRF token or perform referer validation, allowing an attacker to craft a malicious page that, when visited by an authenticated administrator, silently adds a new administrator account [1][2].
Exploitation
An attacker must first trick an authenticated MCMS administrator into visiting a specially crafted HTML page while the administrator's session is active. The attacker can use a tool such as Burp Suite to generate a CSRF payload from the legitimate add-admin request and embed it in a local HTML file. When the administrator opens this file in the same browser where they are logged into MCMS, the request is automatically submitted, creating a new administrative user without the administrator's knowledge or interaction beyond the initial page visit [2].
Impact
Successful exploitation grants the attacker full administrative privileges over the MCMS instance. The attacker can then access and control all CMS functions, including content management, user management, and system configuration, leading to a complete compromise of the application and its data [1][2].
Mitigation
As of the publication date (2022-05-31), no official patch has been released for MCMS 5.2.7. The vendor has not announced a fixed version. Administrators should implement CSRF protections such as adding anti-CSRF tokens to sensitive endpoints, validating the HTTP Referer header, or restricting the use of the affected endpoint to safe methods. Monitoring for unexpected administrator accounts is also recommended [1][2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.mingsoft:ms-mcmsMaven | <= 5.2.7 | — |
Affected products
2- MCMS/MCMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-gp39-qj5f-43qvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-29647ghsaADVISORY
- gist.github.com/aaaahuia/f708c6c8a320e0f3afbb9247903c4670ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.