MEDIUM🇬🇧 English

CVE-2025-13782

CVSS 5.5v4.0pub. 2025-11-30upd. 2026-04-29

Została zidentyfikowana podatność w taosir WTCMS do wersji 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Problem dotyczy funkcji delete w pliku application/Admin/Controller/SlideController.class.php w komponencie SlideController. Manipulacja parametrem ids prowadzi do SQL injection. Atak jest możliwy zdalnie, a exploit jest publicznie dostępny. Producent nie odpowiedział na wcześniejszą notyfikację.

Pokaż oryginał (EN)

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideController. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Wtcms Project Wtcms

    APP
    Wtcms Project
    ≤ 2019-12-20
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLi
CWE
Referencje

Powiązane podatności

CVE-2024-48237CRITICAL9.8PL ✓ten sam produkt

WTCMS 1.0 — błędna kontrola dostępu w HomebaseController

CVE-2019-8908CRITICAL9.8PL ✓ten sam produkt

WTCMS 1.0 — RCE przez upload pliku PHP w konfiguracji szablonu e-mail

CVE-2019-8909HIGH7.5ten sam produkt

An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consum...

CVE-2019-8910HIGH8.8ten sam produkt

An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.

CVE-2018-10267HIGH8.8ten sam produkt

WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post U...