PT-2026-1211 · Bg5Sbk · Minicms
Blackooo
·
Published
2026-01-05
·
Updated
2026-01-10
·
CVE-2025-15457
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bg5sbk MiniCMS versions up to 1.8
Description
A flaw exists in bg5sbk MiniCMS up to version 1.8 related to improper authentication. The issue resides in an unknown function within the
/minicms/mc-admin/post.php file, specifically within the Trash File Restore Handler component. A remote attacker can exploit this flaw through manipulation. The exploit is publicly available. The vendor was notified but did not respond.Recommendations
Versions prior to 1.8 should be updated. As a temporary workaround, consider restricting access to the
/minicms/mc-admin/post.php file to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minicms