Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15456

Опубликовано: 05 янв. 2026
Источник: nvd
CVSS3: 7.3
CVSS3: 7.5
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. The vendor was contacted early about this disclosure but did not respond in any way.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:1234n:minicms:*:*:*:*:*:*:*:*
Версия до 1.8 (включая)

EPSS

Процентиль: 39%
0.00176
Низкий

7.3 High

CVSS3

7.5 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.3
github
около 1 месяца назад

A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 39%
0.00176
Низкий

7.3 High

CVSS3

7.5 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo