PT-2025-49779 · Wbce Cms · Wbce Cms
Published
2025-12-09
·
Updated
2025-12-09
·
CVE-2025-67504
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WBCE CMS versions 1.6.4 and below
Description
WBCE CMS uses the
GenerateRandomPassword() function to create passwords using PHP's rand(). The rand() function is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets.Recommendations
Update WBCE CMS to version 1.6.5.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wbce Cms