CVE-2025-66571
CVE-2025-66571
9.3
CriticalPublished:
Last updated:
Source:disclosure@vulncheck.com
Deferred
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated attackers to inject arbitrary PHP objects and potentially write and execute arbitrary PHP code.
References
disclosure@vulncheck.com
https://github.com/unacms/unadisclosure@vulncheck.com
https://karmainsecurity.com/KIS-2025-01disclosure@vulncheck.com
https://unacms.comdisclosure@vulncheck.com
https://www.exploit-db.com/exploits/52139disclosure@vulncheck.com
https://www.vulncheck.com/advisories/una-cms-900-rc1-1400-rc4-php-object-injection