PoC Index

CVE-2025-50754

CRITICAL 9.6EPSS 0.6%

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.

CVSS v3.1
9.6 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
0.56% chance of exploitation in the next 30 days, 44th percentile
Published
2025-08-04
Updated
2025-08-05

Proof-of-concept exploits (1)

References

Related