CVE-2025-0484
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 15, 2025
CWE ID 285
CWE ID 266
Summary
CVE-2025-0484 is a critical vulnerability affecting Fanli2012 native-php-cms version 1.0. The issue lies in the Backend component's processing of the /fladmin/sysconfig_doedit.php file, resulting in improper authorization. This vulnerability allows an attacker to manipulate the system remotely, putting systems using this software at risk. The exploit for this vulnerability has been made public, increasing the potential threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.