CVE-2022-25369 is a critical pre-authentication logic flaw affecting Dynamicweb versions prior to 9.12.8, including releases 9.5.0 through 9.12.7. Improper handling of the user-controlled Action parameter lets an unauthenticated attacker re-enter the application's setup workflow after installation and access setup actions that should no longer be available.
An attacker can use the exposed workflow to create a privileged administrator account, log in to the administrative panel, and upload an ASPX web shell for server-side command execution. The vulnerable logic reportedly existed from August 2018; Dynamicweb confirmed Assetnote's January 2022 disclosure and issued hotfixed releases to supported branches, with fixes rolled out to customers on January 24, 2022.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The advisory describing the Dynamicweb pre-authentication logic flaw and its path to web-shell-based server-side command execution was published.
Dynamicweb rolled out fixes to customers, including hotfixed releases across supported version branches; versions before 9.12.8 were affected.
Assetnote Security Research Team reported the pre-authentication flaw allowing creation of a Dynamicweb administrator account to Dynamicweb. Dynamicweb's CTO confirmed the issue and supplied fix information the same day.
The vulnerable setup-workflow logic associated with CVE-2022-25369 was reportedly present in a Dynamicweb release from August 2018.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceblog.assetnote.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.