External risk intelligence

Melis Platform melis-core Unauthenticated Administrator Account Creation

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-10352

The vulnerability resides in the Melis Platform, a web-based CMS application. The affected endpoint (/melis/MelisCore/ToolUser/addNewUser) is part of a web application architecture commonly deployed as an internet-facing service. Because this is a web platform, it is frequently exposed to the public internet to facilitate administration or access, making it a likely target for remote, network-based exploitation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Melis Platform's core module could allow an unauthorized attacker to create an administrator account remotely. The platform is used for web-based content management, and if deployed online, could be susceptible to this attack. The main concern is confirming if this technology is in use and if it is exposed externally.

  • Unauthenticated attackers can create admin accounts.
  • Understand if this platform is in your environment.
  • Verify relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending a crafted request to a specific endpoint. This could allow them to create a new administrator account, potentially giving them broad control over the affected system.

  • No authentication required.
  • Triggered by a request to '/melis/MelisCore/ToolUser/addNewUser'.
  • Allows creation of an administrator account.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could create an administrator account on the Melis Platform by sending a crafted request to a specific endpoint. This could allow them to gain administrative privileges without needing any prior credentials when supported by the advisory.

  • Administrator account creation.
  • Network request to a specific endpoint.
  • Unauthorized administrative access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Melis Platform's melis-core module, specifically the `/melis/MelisCore/ToolUser/addNewUser` endpoint, is vulnerable to unauthenticated administrator account creation. This critical vulnerability is likely exploitable over the network. Responsibility for addressing this issue typically falls to the platform or application owners, in coordination with infrastructure and security teams. The immediate first step should be to identify all instances of the Melis Platform within the environment, determine their exposure (internal vs. external), and assess business criticality to prioritize remediation efforts.

  • Platform owners must confirm deployment scope.
  • Verify external reachability and business criticality.
  • Plan coordinated remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Melis Platform?

The Melis Platform is a web-based content management system (CMS) designed to help organizations build and manage digital sites. Its melis-core module provides essential background functionality, including user and administrative management tools, which are necessary for the platform to handle site operations and backend administrative tasks.

What does CVE-2025-10352 mean for the platform?

This vulnerability is classified as CWE-862, which refers to a Missing Authorization flaw. In plain terms, the system fails to check if a person has permission to perform a sensitive action. Specifically, it allows anyone on the network to interact with a user-creation tool that should be restricted to existing administrators only.

How can an attacker trigger this vulnerability?

An attacker can trigger this issue by sending a specially crafted network request to the '/melis/MelisCore/ToolUser/addNewUser' endpoint. No special login or prior account access is required to initiate the request. The vulnerability is not triggered by normal site browsing or legitimate administrative actions; it specifically requires targeting this backend management URL.

Is my system at risk according to Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is likely to affect your systems if you run the Melis Platform in an internet-facing configuration. Because the platform is a web-based application, it is often deployed publicly to allow remote management, which makes that specific user-creation endpoint reachable by unauthorized parties over the network.

What steps should I take if I use Melis Platform?

Your first priority is to locate all deployments of the Melis Platform across your infrastructure. Determine if these instances are accessible from the internet or restricted to internal networks. Once identified, consult with your development or security teams to restrict access to the affected endpoint and review administrative account logs for any unexpected changes.

References