CVE detail
CVE-2020-25557 — CVE-2020-25557
Published 2020-11-13 · Modified 2026-06-17 · Vendor cmsuno_project · Product cmsuno · Source nvd
HIGH
severity
CVSS-derived band
0.0997
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References