The 2023 Pwnie Nominee For Lamest Vendor Response

Authentication Bypass in Mura CMS

Mura Software

After a legitimate researcher disclosed an authentication bypass in Mura CMS, Mura Software claimed credit for the bug themselves and then charged customers $5000 to fix it. https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html. Not cool, Mura. Booooooo.