PT-2026-1209 · Bg5Sbk · Minicms

Blackooo

·

Published

2026-01-05

·

Updated

2026-01-21

·

CVE-2025-15455

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions bg5sbk MiniCMS versions up to 1.8
Description A flaw exists in bg5sbk MiniCMS up to version 1.8 related to improper authentication. The issue is located in the delete page function within the /minicms/mc-admin/page.php file of the File Recovery Request Handler component. This manipulation allows for remote exploitation. The exploit has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions prior to 1.8 should be updated. As a temporary workaround, consider restricting access to the /minicms/mc-admin/page.php file.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15455

Affected Products

Minicms