Description
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.
Published: 2026-07-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the step5 function of the installation controller allows an attacker to bypass authorization checks during the setup process. This flaw is an the installation module, potentially enabling further privileged operations. The vulnerability can be exploited remotely and would allow an attacker to manipulate installation parameters without proper authentication. The exploit is noted as difficult, and the only publicly available exploit has been disclosed.

Affected Systems

MacCMS Pro is affected when running any version up to 2022.1000.3005. The vulnerability resides in the application/install/controller/Index.php component of the Installation Module. The vendor recommends upgrading to version 2022.1000.3025 to remediate the issue. No other vendor or product versions are mentioned as impacted.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. The EPSS score of <1% shows a low probability of exploitation in the near term. The attack requires high complexity and is considered difficult to execute. The weakness is identified by CWE‑285 and CWE‑639, highlighting a failure in enforcing proper authorization.

Generated by OpenCVE AI on August 1, 2026 at 11:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MacCMS Pro to version 2022.1000.3025 to apply the vendor fix
  • Replace the installation module component with the updated version from the official release
  • Configure the web server to restrict access to the installation module only to authenticated administrators (e.g., via IP allowlist or HTTP authentication)

Generated by OpenCVE AI on August 1, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Magicblack
Magicblack maccms Pro
Vendors & Products Magicblack
Magicblack maccms Pro

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.
Title MacCMS Pro Installation Index.php step5 authorization
First Time appeared Maccms Pro
Maccms Pro maccms Pro
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:maccms_pro:maccms_pro:*:*:*:*:*:*:*:*
Vendors & Products Maccms Pro
Maccms Pro maccms Pro
References
Metrics cvssV2_0

{'score': 5.1, 'vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.6, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Maccms Pro Maccms Pro
Magicblack Maccms Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T15:22:08.631Z

Reserved: 2026-07-12T11:05:41.518Z

Link: CVE-2026-15516

cve-icon Vulnrichment

Updated: 2026-07-13T15:20:34.915Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key