PT-2025-7590 · Phpcmsv9 · Phpcmsv9

Trymonoly

·

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2025-25960

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpcmsv9 version 9.6.3
Description The issue allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator. This is a Cross-Site Scripting issue.
Recommendations For phpcmsv9 version 9.6.3, update to a version that fixes this issue to prevent privilege escalation. As a temporary workaround, consider restricting access to the menu interface of the member center of the background administrator to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-25960

Affected Products

Phpcmsv9