PT-2025-50504 · Wbce Cms · Wbce Cms
Published
2025-12-10
·
Updated
2025-12-11
·
CVE-2025-65950
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WBCE CMS versions prior to 1.6.5
Description
WBCE CMS is a content management system. Versions 1.6.4 and below contain a flaw in the user management module that allows a low-privileged authenticated user with user modification permissions to execute arbitrary SQL queries. Successful exploitation could lead to a full database compromise and data exfiltration, bypassing security controls. The issue resides in the
admin/users/save.php script, specifically in how it handles the groups[] parameter from the user edit form.Recommendations
Update WBCE CMS to version 1.6.5 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wbce Cms