A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 07:15:00 +0900

Type Values Removed Values Added
First Time appeared 1234n
1234n minicms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:1234n:minicms:*:*:*:*:*:*:*:*
Vendors & Products 1234n
1234n minicms

Wed, 07 Jan 2026 06:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 19:45:00 +0900

Type Values Removed Values Added
First Time appeared Bg5sbk
Bg5sbk minicms
Vendors & Products Bg5sbk
Bg5sbk minicms

Mon, 05 Jan 2026 13:00:00 +0900

Type Values Removed Values Added
Description A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title bg5sbk MiniCMS File Recovery Request page.php delete_page improper authentication
Weaknesses CWE-287
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-01-06T18:50:34.710Z

Reserved: 2026-01-04T10:27:32.057Z

Link: CVE-2025-15455

cve-icon Vulnrichment

Updated: 2026-01-06T18:50:28.034Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-05T04:15:41.600

Modified: 2026-01-21T22:01:58.440

Link: CVE-2025-15455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-05T19:13:23Z

Weaknesses