PT-2026-1209 · Bg5Sbk · Minicms
Blackooo
·
Published
2026-01-05
·
Updated
2026-01-21
·
CVE-2025-15455
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
bg5sbk MiniCMS versions up to 1.8
Description
A flaw exists in bg5sbk MiniCMS up to version 1.8 related to improper authentication. The issue is located in the
delete page function within the /minicms/mc-admin/page.php file of the File Recovery Request Handler component. This manipulation allows for remote exploitation. The exploit has been published. The vendor was contacted regarding this disclosure but did not respond.Recommendations
Versions prior to 1.8 should be updated. As a temporary workaround, consider restricting access to the
/minicms/mc-admin/page.php file.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minicms