CVE-2025-65950 is a critical SQL injection vulnerability affecting WBCE CMS versions 1.6.4 and below, specifically within the user management module's admin/users/save.php script. A low-privileged authenticated user can exploit this flaw by manipulating the groups[] parameter to execute arbitrary SQL queries, leading to full database compromise, data exfiltration, and complete bypass of security controls. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 90/100, this vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code, active exploitation, or significant community discussion has been observed, the potential for severe damage necessitates immediate patching to version 1.6.5 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.5CPE matchmatch criteria | cpe:2.3:a:wbce:wbce_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.