PT-2025-23612 · Phpcms · Phpcms
Dem0
+1
·
Published
2025-06-03
·
Updated
2025-08-20
·
CVE-2025-5497
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpwcms versions 1.9.45 through 1.10.8
Description
A critical vulnerability was found in the Feedimport Module of phpwcms, affecting unknown code in the file include/inc module/mod feedimport/inc/processing.inc.php. The manipulation of the
cnt text argument leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
To address this issue, upgrade to version 1.9.46 or 1.10.9. As a temporary workaround, consider restricting access to the Feedimport Module until the issue is resolved. Avoid using the
cnt text argument in the affected module until the issue is resolved.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpcms