PT-2025-50504 · Wbce Cms · Wbce Cms

CVE-2025-65950

·

Published

2025-12-10

·

Updated

2025-12-11

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WBCE CMS versions prior to 1.6.5
Description WBCE CMS is a content management system. Versions 1.6.4 and below contain a flaw in the user management module that allows a low-privileged authenticated user with user modification permissions to execute arbitrary SQL queries. Successful exploitation could lead to a full database compromise and data exfiltration, bypassing security controls. The issue resides in the admin/users/save.php script, specifically in how it handles the groups[] parameter from the user edit form.
Recommendations Update WBCE CMS to version 1.6.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65950
GHSA-934V-XHX9-J2F3

Affected Products

Wbce Cms