Path Traversal Vulnerability in PowerCMS by PowerCMS
CVE-2025-46359
Key Information:
- Vendor
Alfasado Inc.
- Status
- Vendor
- CVE Published:
- 31 July 2025
Badges
What is CVE-2025-46359?
A path traversal vulnerability has been identified in the backup and restore features of multiple versions of PowerCMS. This flaw allows product administrators to execute arbitrary code by restoring a crafted backup file. This issue emphasizes the importance of securing backup functionalities within content management systems to prevent unauthorized code execution, potentially compromising server integrity and data confidentiality.
Affected Version(s)
PowerCMS 6.7 and earlier (PowerCMS 6.x series)
PowerCMS 5.3 and earlier (PowerCMS 5.x series)
PowerCMS 4.6 and earlier (PowerCMS 4.x series)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
