S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-25369 Scanner

Detects 'Unauthenticated Admin User Creation' vulnerability in Dynamicweb affects v. 9.5.0 - 9.12.7.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25369
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Dynamicweb is a popular content management system designed to help create and manage professional websites. It is often used by small to medium-sized businesses that require a flexible and scalable platform to build and enhance their businesses online. The platform offers a range of powerful modules, including e-commerce, marketing automation, and content management, which enable businesses to customize and optimize their online presence to meet their specific needs.

Unfortunately, the platform has been found to contain a severe vulnerability, identified as CVE-2022-25369. This vulnerability allows an unauthenticated attacker to create a new administrative user, providing them with complete control and access to the entire site. The attacker can also allocate administrative privileges to other users, leaving the site open to further exploitation.

The consequences of exploiting this vulnerability can be catastrophic for businesses. An attacker could potentially take over the entire site, steal sensitive information, and disrupt normal site operations. In the hands of a malicious actor, this vulnerability could lead to devastating financial losses, loss of critical data, and damage to a company's reputation.

At s4e.io, we understand the importance of protecting online business assets and digital information. With our powerful security features and tools, businesses can rest assured that their online presence is protected. Our platform offers advanced threat detection, vulnerability scanning, and security alerts to ensure maximum protection for our clients. With s4e.io, businesses can stay on top of potential threats and vulnerabilities to keep their online presence safe and secure.

 

REFERENCES

 

Solution Advice

To protect against this vulnerability, businesses using Dynamicweb should take the following precautions:

  • Upgrade to one of the fixed versions or higher: Dynamicweb 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9, 9.10.18, 9.12.8, or 9.13.0.
  • Regularly monitor site activity to detect any suspicious activity promptly.
  • Enable two-factor authentication to add an extra layer of security.
  • Review user access permissions regularly and remove access to unnecessary users.
  • Implement a web application firewall to protect against malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.