PT-2025-49139 · Una Cms · Unak-Cms

Published

2025-12-04

·

Updated

2025-12-05

·

CVE-2025-66571

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UNA CMS versions 9.0.0-RC1 through 14.0.0-RC4
Description The software contains a PHP object injection issue in the BxBaseMenuSetAclLevel.php component. The profile id POST parameter is passed to the PHP unserialize() function without sufficient validation, potentially allowing remote, unauthenticated attackers to inject arbitrary PHP objects and execute code.
Recommendations Versions 9.0.0-RC1 through 14.0.0-RC4: Ensure proper handling of the profile id POST parameter before passing it to the PHP unserialize() function.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-66571

Affected Products

Unak-Cms