Junglewise Threat Intelligence

CVE-2025-50581: MRCMS XSS in admin group management

CVE-2025-50581 · Severity: medium · CVSS 4.8 · Published 2025-07-18

Executive brief

MRCMS, a content management system, contains a security flaw in its administrative group management feature. An attacker with administrative access could inject malicious scripts into group names or descriptions, which would then execute in the browser of other users viewing those pages. This could lead to unauthorized actions being performed in the context of another user's session or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in MRCMS v3.1.2 within the group management functionality. The vulnerability is located in the /admin/group/save.do component, which fails to properly neutralize user-supplied input before it is stored and subsequently rendered in the web interface. An attacker with high privileges (administrative access) can inject malicious JavaScript into the 'group name' or 'group description' fields. When another user views the affected group management page, the script executes in their browser. The attack requires network connectivity and minimal user interaction (viewing the compromised page). A Proof of Concept (PoC) has been publicly disclosed.

Affected products

  • MRCMS MRCMS 3.1.2

Timeline

  • 2025-07-18: disclosed: Vulnerability reported on GitHub issues and published by MITRE
  • 2025-07-18: advisory: NVD published the CVE record

References