Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.
History

Tue, 05 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
References

Mon, 04 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-04T00:00:00.000Z

Updated: 2025-08-05T14:21:42.137Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50754

cve-icon Vulnrichment

Updated: 2025-08-05T14:21:38.067Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-04T21:15:30.400

Modified: 2025-08-05T15:15:30.370

Link: CVE-2025-50754

cve-icon Redhat

No data.