Impact
A flaw in the step5 function of the installation controller allows an attacker to bypass authorization checks during the setup process. This flaw is an the installation module, potentially enabling further privileged operations. The vulnerability can be exploited remotely and would allow an attacker to manipulate installation parameters without proper authentication. The exploit is noted as difficult, and the only publicly available exploit has been disclosed.
Affected Systems
MacCMS Pro is affected when running any version up to 2022.1000.3005. The vulnerability resides in the application/install/controller/Index.php component of the Installation Module. The vendor recommends upgrading to version 2022.1000.3025 to remediate the issue. No other vendor or product versions are mentioned as impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. The EPSS score of <1% shows a low probability of exploitation in the near term. The attack requires high complexity and is considered difficult to execute. The weakness is identified by CWE‑285 and CWE‑639, highlighting a failure in enforcing proper authorization.
OpenCVE Enrichment