CVE-2022-25369
moderateUnauthenticated Admin User Creation and RCE in Dynamicweb
Dynamicweb, a CMS and e-commerce platform, contains an authentication-bypass flaw (CWE-287/CWE-288) in the logic that determines whether the product's setup phases can be re-run, allowing an unauthenticated network attacker to create a new administrator user. After creating that account, the attacker logs in with it and can upload an executable file, escalating the compromise to arbitrary command execution on the server. Any Dynamicweb deployment running a version older than the patched release for its branch is affected, with no authentication or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, but the EPSS score of 40.7% (99th percentile) indicates a substantial likelihood of exploitation within 30 days. Defenders should treat internet-facing Dynamicweb instances as high-priority patch targets.
What to do: Upgrade affected deployments to the fixed release for their branch: 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, or 9.13.0 (or later). As an interim mitigation, restrict network access to the Dynamicweb setup/admin endpoints from untrusted sources, and audit the administrator user list for recently created or unrecognized accounts plus any unexpectedly uploaded executable files.
| Dynamicweb (CMS/e-commerce platform) | All versions before 9.12.8; fixed per branch in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 and later |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).
- Weakness
- CWE-287, CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.