Executive brief
MacCMS Pro, a popular content management system for video sites, contains a flaw in its installation module. An attacker can bypass security locks to re-run the installation process on an already active website. This allows them to overwrite the site's configuration and create a new administrative account, effectively taking full control of the website and its data.
Technical details
An authorization bypass vulnerability exists in MacCMS Pro (also known as AppleCMS V10) within the `step5` function of `application/install/controller/Index.php`. The application fails to verify the existence of the `install.lock` file before executing the final installation step. A remote, unauthenticated attacker can exploit this by sending a specifically crafted POST request to the installation endpoint, providing new administrator credentials and configuration parameters. This results in the re-initialization of the database and the creation of a new administrative user. The vulnerability is addressed in version 2022.1000.3025 by implementing a global check to disable the installation module once the lock file is present.
Affected products
- magicblack MacCMS Pro up to 2022.1000.3005
Timeline
- 2026-07-13: advisory: NVD publication date
- 2022-03-20: patched: Vendor release v2022.1000.3025 addressing security issues