Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/furk4nyildiz/CVE-2025-50754-PoC |
![]() ![]() ![]() |
History
Tue, 05 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 05 Aug 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 04 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-04T00:00:00.000Z
Updated: 2025-08-05T14:21:42.137Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50754

Updated: 2025-08-05T14:21:38.067Z

Status : Awaiting Analysis
Published: 2025-08-04T21:15:30.400
Modified: 2025-08-05T15:15:30.370
Link: CVE-2025-50754

No data.