CVE Explorer
CVE-2026-40174
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management operations.
An attacker can induce a logged-in administrator to submit a forged request that adds, modifies, or deletes user address records, including email addresses and phone numbers. This can be used to alter contact information, redirect organizational communications, and corrupt address data i
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"MasaCMS","vendor":"MasaCMS","versions":[{"status":"affected","version":"< 7.2.10"},{"status":"affected","version":">= 7.3.0, < 7.3.15"},{"status":"affected","version":">= 7.4.0, < 7.4.10"},{"status":"affected","version":">= 7.5.0, < 7.5.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:afcd1c6ee417ce6adbeb6cb1b5079e67a929944a96f6dca5c7b36397d145f32e · sha256:0ff311d9b49fd0e3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:afcd1c6ee417ce6adbeb6cb1b5079e67a929944a96f6dca5c7b36397d145f32e · sha256:0ff311d9b49fd0e3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:afcd1c6ee417ce6adbeb6cb1b5079e67a929944a96f6dca5c7b36397d145f32e · sha256:0ff311d9b49fd0e3… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-572m-p246-4356","tags":["x_refsource_CONFIRM"],"url":"https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-572m-p246-4356"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:afcd1c6ee417ce6adbeb6cb1b5079e67a929944a96f6dca5c7b36397d145f32e · sha256:0ff311d9b49fd0e3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.