PT-2026-1209 · Bg5Sbk · Minicms

Blackooo

·

Publicado

2026-01-05

·

Atualizado

2026-01-21

·

CVE-2025-15455

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions bg5sbk MiniCMS versions up to 1.8
Description A flaw exists in bg5sbk MiniCMS up to version 1.8 related to improper authentication. The issue is located in the delete page function within the /minicms/mc-admin/page.php file of the File Recovery Request Handler component. This manipulation allows for remote exploitation. The exploit has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions prior to 1.8 should be updated. As a temporary workaround, consider restricting access to the /minicms/mc-admin/page.php file.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15455

Produtos afetados

Minicms