Description

WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration, effectively bypassing all security controls. The vulnerability exists in the admin/users/save.php script, which handles updates to user profiles. The script improperly processes the groups[] parameter sent from the user edit form. This issue is fixed in version 1.6.5.

INFO

Published Date :

2025-12-10T20:39:27.452Z

Last Modified :

2025-12-10T21:24:43.064Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-65950 vulnerability.

Vendors Products
Wbce
  • Wbce Cms

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability