CVE-2025-29150

BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:bluecms_project:bluecms:1.6:*:*:*:*:*:*:*

History

15 Apr 2025, 13:50

Type Values Removed Values Added
First Time Bluecms Project bluecms
Bluecms Project
References () https://gist.github.com/electroN1chahaha/054a1af22157aa3010e89b3103ad7b9a - () https://gist.github.com/electroN1chahaha/054a1af22157aa3010e89b3103ad7b9a - Exploit, Third Party Advisory
CPE cpe:2.3:a:bluecms_project:bluecms:1.6:*:*:*:*:*:*:*

11 Apr 2025, 15:39

Type Values Removed Values Added
Summary
  • (es) BlueCMS 1.6 sufre eliminación arbitraria de archivos a través del parámetro id en una solicitud /publish.php?act=del.

10 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 15:16

Updated : 2025-04-15 13:50


NVD link : CVE-2025-29150

Mitre link : CVE-2025-29150

CVE.ORG link : CVE-2025-29150


JSON object : View

Products Affected

bluecms_project

  • bluecms
CWE
CWE-20

Improper Input Validation