PT-2025-48382 · Unknown · Taosir Wtcms

St1Tch

·

Published

2025-11-30

·

Updated

2025-11-30

·

CVE-2025-13782

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions taosir WTCMS versions prior to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
Description A flaw exists in the
delete
function within the
SlideController.class.php
file of the SlideController component. Manipulation of the
ids
argument can lead to SQL injection. Remote exploitation is possible. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations Versions prior to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665 should be updated. As a temporary workaround, consider restricting access to the
SlideController
component or disabling the
delete
function until a patch is available.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13782

Affected Products

Taosir Wtcms