PT-2025-51952 · Ulicms · Ulicms

Mirabbas Ağalarov

·

Published

2025-12-17

·

Updated

2025-12-24

·

CVE-2023-53914

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UliCMS version 2023.1
Description An authentication bypass allows unauthenticated attackers to create administrative users. This is possible through mass assignment in the UserController by sending a crafted POST request to the ''index.php'' endpoint. Successful exploitation grants attackers full system access. The vulnerable parameter is not explicitly mentioned.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-53914

Affected Products

Ulicms