PT-2025-47517 · Wbce Cms · Wbce Cms

Published

2025-11-19

·

Updated

2025-12-15

·

CVE-2025-65094

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WBCE CMS versions prior to 1.6.4
Description A low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the '/admin/users/save.php' request. The user interface restricts group assignments to existing memberships, but server-side validation is absent, enabling attackers to overwrite their group membership and gain full administrative access, leading to a complete compromise of the CMS. The API endpoint ''/admin/users/save.php'' is vulnerable, specifically through the groups[] parameter.
Recommendations Update to version 1.6.4 or later.

Exploit

Fix

LPE

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-65094
GHSA-HMMW-4CCM-FX44

Affected Products

Wbce Cms