PT-2026-1209 · Bg5Sbk · Minicms
Blackooo
·
Publicado
2026-01-05
·
Atualizado
2026-01-21
·
CVE-2025-15455
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
bg5sbk MiniCMS versions up to 1.8
Description
A flaw exists in bg5sbk MiniCMS up to version 1.8 related to improper authentication. The issue is located in the
delete page function within the /minicms/mc-admin/page.php file of the File Recovery Request Handler component. This manipulation allows for remote exploitation. The exploit has been published. The vendor was contacted regarding this disclosure but did not respond.Recommendations
Versions prior to 1.8 should be updated. As a temporary workaround, consider restricting access to the
/minicms/mc-admin/page.php file.Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Minicms