ZeroHour

CVE-2022-25369

moderate

Unauthenticated Admin User Creation and RCE in Dynamicweb

CVSS 3.1
9.8 critical
EPSS
41%p99
Published
()
Modified
AI analysis

Dynamicweb, a CMS and e-commerce platform, contains an authentication-bypass flaw (CWE-287/CWE-288) in the logic that determines whether the product's setup phases can be re-run, allowing an unauthenticated network attacker to create a new administrator user. After creating that account, the attacker logs in with it and can upload an executable file, escalating the compromise to arbitrary command execution on the server. Any Dynamicweb deployment running a version older than the patched release for its branch is affected, with no authentication or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, but the EPSS score of 40.7% (99th percentile) indicates a substantial likelihood of exploitation within 30 days. Defenders should treat internet-facing Dynamicweb instances as high-priority patch targets.

What to do: Upgrade affected deployments to the fixed release for their branch: 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, or 9.13.0 (or later). As an interim mitigation, restrict network access to the Dynamicweb setup/admin endpoints from untrusted sources, and audit the administrator user list for recently created or unrecognized accounts plus any unexpectedly uploaded executable files.

Affected
Dynamicweb (CMS/e-commerce platform)All versions before 9.12.8; fixed per branch in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 and later
Estimated exposure
moderateroughly 1,000-10,000 installations — Dynamicweb is a European (largely Nordic) CMS/commerce platform with a far smaller footprint than mainstream CMS products, so public exposure is plausibly in the low thousands of internet-facing sites, not tens of thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).

Weakness
CWE-287, CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.