216.73.216.6

CVE-2025-50754

· Published 04/08/2025 21:15 · Modified 05/08/2025 15:15

Labels: CVE-2025-50754 2025-08-04CVE-2025-50754CWE-79[email protected]

Essential information

Published
04/08/2025 21:15
Modified
05/08/2025 15:15
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
unisite / cms cpe:2.3:a:unisite:cms:5.0:*:*:*:*:*:*:*

References