CVE-2025-5498 | slackero phpwcms up to 1.9.45/1.10.8 Custom Source Tab cnt21.readform.inc.php file_get_contents/is_file cpage_custom deserialization
A vulnerability classified as critical was found in slackero phpwcms up to 1.9.45/1.10.8. This affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. Executing a manipulation of the argument cpage_custom can lead to deserialization.
This vulnerability is tracked as CVE-2025-5498. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.