PT-2025-48783 · Feehicms · Feehicms

Kiwi865

·

Published

2025-12-02

·

Updated

2025-12-05

·

CVE-2025-65657

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FeehiCMS version 2.1.1
Description FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes without sufficient validation. An attacker can upload a crafted PHP file, causing the application or web server to execute it, resulting in remote code execution (RCE). The issue resides in Ad Management.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-65657
GHSA-MCXQ-54F4-MMX5

Affected Products

Feehicms