BoyunCMS Installation install2.php deserialization

CVE Details

Basic Information

Title BoyunCMS Installation install2.php deserialization
Type cve
Published 2025-07-06T23:32:07.369Z
Modified 2025-07-06T23:32:07.369Z

Product Information

Vendor n/a
Product BoyunCMS
Version 1.0

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Affected Products

  • n/a BoyunCMS 1.0
  • n/a BoyunCMS 1.1
  • n/a BoyunCMS 1.2
  • n/a BoyunCMS 1.3
  • n/a BoyunCMS 1.4
  • n/a BoyunCMS 1.5
  • n/a BoyunCMS 1.6
  • n/a BoyunCMS 1.7
  • n/a BoyunCMS 1.8
  • n/a BoyunCMS 1.9
  • n/a BoyunCMS 1.10
  • n/a BoyunCMS 1.11
  • n/a BoyunCMS 1.12
  • n/a BoyunCMS 1.13
  • n/a BoyunCMS 1.14
  • n/a BoyunCMS 1.15
  • n/a BoyunCMS 1.16
  • n/a BoyunCMS 1.17
  • n/a BoyunCMS 1.18
  • n/a BoyunCMS 1.19
  • n/a BoyunCMS 1.20
  • n/a BoyunCMS 1.21

Additional Information

CWE List CWE-502, CWE-20
Source VulDB

Description

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to deserialization. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.