A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been declared as critical. This vulnerability affects unknown code of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport Module. The manipulation of the argument cnt_text leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.
History

Fri, 13 Jun 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Phpwcms
Phpwcms phpwcms
CPEs cpe:2.3:a:phpwcms:phpwcms:*:*:*:*:*:*:*:*
Vendors & Products Phpwcms
Phpwcms phpwcms

Tue, 03 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been declared as critical. This vulnerability affects unknown code of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport Module. The manipulation of the argument cnt_text leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.
Title slackero phpwcms Feedimport Module processing.inc.php deserialization
Weaknesses CWE-20
CWE-502
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-06-03T13:00:16.567Z

Updated: 2025-06-03T14:45:34.792Z

Reserved: 2025-06-03T05:14:32.944Z

Link: CVE-2025-5497

cve-icon Vulnrichment

Updated: 2025-06-03T14:45:28.330Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-03T13:15:21.310

Modified: 2025-06-13T19:44:32.447

Link: CVE-2025-5497

cve-icon Redhat

No data.