CVE Explorer
CVE-2025-66571
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated attackers to inject arbitrary PHP objects and potentially write and execute arbitrary PHP code.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"UNA CMS","vendor":"Unknown","versions":[{"lessThanOrEqual":"14.0.0-RC4","status":"affected","version":"9.0.0-RC1","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502: Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"UNA CMS GitHub Repository","tags":["product"],"url":"https://github.com/unacms/una"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/references/2
{"name":"Karma Security Advisory","tags":["vdb-entry"],"url":"https://karmainsecurity.com/KIS-2025-01"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/references/3
{"name":"UNA CMS Homepage","tags":["product"],"url":"https://unacms.com"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/references/1
{"name":"ExploitDB-52139","tags":["exploit"],"url":"https://www.exploit-db.com/exploits/52139"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/una-cms-900-rc1-1400-rc4-php-object-injection"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f49725327ce15816e68fd1fd251fc460e6d62fdac80796d09bc853ced2bdbc2a · sha256:1d8d0aa6420d0882… · /containers/cna/references/4
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.