UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.
History

Thu, 18 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ulicms
Ulicms ulicms
Vendors & Products Ulicms
Ulicms ulicms

Wed, 17 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.
Title UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-17T22:44:49.556Z

Updated: 2025-12-18T15:03:56.460Z

Reserved: 2025-12-16T19:22:09.995Z

Link: CVE-2023-53914

cve-icon Vulnrichment

Updated: 2025-12-18T14:50:23.166Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-17T23:15:49.983

Modified: 2025-12-18T15:15:50.357

Link: CVE-2023-53914

cve-icon Redhat

No data.