Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability in the Melis Platform's core module could allow an unauthorized attacker to create an administrator account remotely. The platform is used for web-based content management, and if deployed online, could be susceptible to this attack. The main concern is confirming if this technology is in use and if it is exposed externally.
- Unauthenticated attackers can create admin accounts.
- Understand if this platform is in your environment.
- Verify relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by sending a crafted request to a specific endpoint. This could allow them to create a new administrator account, potentially giving them broad control over the affected system.
- No authentication required.
- Triggered by a request to '/melis/MelisCore/ToolUser/addNewUser'.
- Allows creation of an administrator account.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated attacker could create an administrator account on the Melis Platform by sending a crafted request to a specific endpoint. This could allow them to gain administrative privileges without needing any prior credentials when supported by the advisory.
- Administrator account creation.
- Network request to a specific endpoint.
- Unauthorized administrative access.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Melis Platform's melis-core module, specifically the `/melis/MelisCore/ToolUser/addNewUser` endpoint, is vulnerable to unauthenticated administrator account creation. This critical vulnerability is likely exploitable over the network. Responsibility for addressing this issue typically falls to the platform or application owners, in coordination with infrastructure and security teams. The immediate first step should be to identify all instances of the Melis Platform within the environment, determine their exposure (internal vs. external), and assess business criticality to prioritize remediation efforts.
- Platform owners must confirm deployment scope.
- Verify external reachability and business criticality.
- Plan coordinated remediation based on risk.