CVE-2025-55040 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability affecting MuraCMS through version 10.1.10, specifically within its form import functionality. This flaw (CVSS 8.8) allows an attacker to install malicious form definitions by tricking an authenticated administrator into visiting a crafted webpage and selecting a malicious ZIP file. Successful exploitation could lead to the creation of data collection forms designed to steal sensitive user information, impacting confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:murasoftware:mura_cms:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.