216.73.217.22

CVE-2025-65094

· Published 19/11/2025 19:15 · Modified 15/12/2025 14:10

Labels: CVE-2025-65094 2025-11-19CVE-2025-65094CWE-266[email protected]

Essential information

Published
19/11/2025 19:15
Modified
15/12/2025 14:10
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only their existing group, but server-side validation is missing, allowing attackers to overwrite their group membership and obtain full administrative access. This results in a complete compromise of the CMS. This issue has been patched in version 1.6.4.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wbce / wbce cms cpe:2.3:a:wbce:wbce_cms:*:*:*:*:*:*:*:*

References