PT-2025-48385 · Unknown · Taosir Wtcms

St1Tch

·

Published

2025-11-30

·

Updated

2025-12-25

·

CVE-2025-13783

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions taosir WTCMS versions up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
Description A security flaw exists in taosir WTCMS. The issue affects the check/uncheck/delete function within the application/Comment/Controller/CommentadminController.class.php file of the CommentadminController component. Manipulation of the ids argument can lead to SQL injection. The attack can be executed remotely. The exploit has been released publicly. The product uses a rolling release model, making specific version information unavailable. The vendor was contacted regarding this disclosure but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13783

Affected Products

Taosir Wtcms