CRITICAL
WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameter
Published Dec 10, 2025
9.4
CRITICALCVSS 4.0
EPSS 0.54%
Description
WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration, effectively bypassing all security controls. The vulnerability exists in the admin/users/save.php script, which handles updates to user profiles. The script improperly processes the groups[] parameter sent from the user edit form. This issue is fixed in version 1.6.5.
Affected products
-
- Version < 1.6.5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/WBCE/WBCE_CMS/commit/96046178f4c80cf16f7c224054dec7fdadddda7e x_refsource_MISCPatch
- https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.5 x_refsource_MISCRelease Notes
- https://github.com/WBCE/WBCE_CMS/security/advisories/GHSA-934v-xhx9-j2f3 x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/WBCE/WBCE_CMS/commit/96046178f4c80cf16f7c224054dec7fdadddda7e | x_refsource_MISCPatch | |
| https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.5 | x_refsource_MISCRelease Notes | |
| https://github.com/WBCE/WBCE_CMS/security/advisories/GHSA-934v-xhx9-j2f3 | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 10, 2025
Updated Dec 10, 2025
Reserved Nov 18, 2025
Link CVE-2025-65950
CISA Vulnrichment
Updated Dec 10, 2025