PT-2025-3912 · Fanli2012 · Native-Php-Cms

Lvzc

+1

·

Published

2025-01-15

·

Updated

2025-04-29

·

CVE-2025-0482

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Fanli2012 native-php-cms version 1.0
Description A critical vulnerability was found in the software, affecting an unknown part of the file /fladmin/user recoverpwd.php. The manipulation leads to the use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Fanli2012 native-php-cms version 1.0, consider disabling access to the /fladmin/user recoverpwd.php file until a patch is available. Restrict the use of default credentials to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-0482

Affected Products

Native-Php-Cms