CVE 6.9 MEDIUM

bg5sbk MiniCMS Trash File Restore post.php improper authentication_CVE-2025-15457

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-15457
Source VulDB
Published Jan 5, 2026 at 04:32

Affected Product

Vendor bg5sbk
Product MiniCMS
Version 1.0
Affected Versions bg5sbk MiniCMS 1.0
bg5sbk MiniCMS 1.1
bg5sbk MiniCMS 1.2
bg5sbk MiniCMS 1.3
bg5sbk MiniCMS 1.4
bg5sbk MiniCMS 1.5
bg5sbk MiniCMS 1.6
bg5sbk MiniCMS 1.7
bg5sbk MiniCMS 1.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.