CVE-2017-15639: Getmura Mura CMS

Medium severity, CVSS 6.5. EPSS: 6.8% chance of exploitation in the next 30 days.

tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.

Affected products

  • Getmura Mura CMS: up to and including 6.1

Published 2017-10-19. Last modified 2026-06-17.