CVE-2025-55824

ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtain sensitive data on the server.
References
Link Resource
https://gist.github.com/CTRLCCT/8f314998f30a95262e512b5417151ea1 Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:modstart:mostartcms:9.5.0:*:*:*:*:*:*:*

History

05 Sep 2025, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:modstart:mostartcms:9.5.0:*:*:*:*:*:*:*
References () https://gist.github.com/CTRLCCT/8f314998f30a95262e512b5417151ea1 - () https://gist.github.com/CTRLCCT/8f314998f30a95262e512b5417151ea1 - Third Party Advisory, Exploit
First Time Modstart
Modstart mostartcms

03 Sep 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-77

02 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 18:15

Updated : 2025-09-05 18:06


NVD link : CVE-2025-55824

Mitre link : CVE-2025-55824

CVE.ORG link : CVE-2025-55824


JSON object : View

Products Affected

modstart

  • mostartcms
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')