Junglewise Threat Intelligence

CVE-2025-52161: Scholl Communications Weblication CMS Core stored XSS in admin panel

CVE-2025-52161 · Severity: critical · CVSS 9.8 · Published 2025-09-08

Executive brief

Weblication CMS, a platform used for building and managing websites, contains a security flaw that allows unauthorized individuals to inject malicious code into the administration panel. By using a specially crafted web link, an attacker can permanently store this code on the site, potentially leading to the theft of administrator credentials or full control over the website's content. This vulnerability is particularly serious because it does not require a password to exploit and affects the core management interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Scholl Communications AG Weblication CMS Core v019.004.000.000. The flaw is located within the admin panel, where user-supplied input via specially crafted URLs is not properly neutralized before being stored and rendered. An unauthenticated remote attacker can exploit this by sending a malicious request that injects persistent JavaScript into the management interface. When an administrative user views the affected section, the script executes in their browser context, potentially allowing for session hijacking or unauthorized configuration changes. The vendor has released version 019.005.000.000 to address this issue.

Affected products

  • Scholl Communications AG Weblication CMS Core 019.004.000.000

Timeline

  • 2025-05-07: disclosed: Initial contact with vendor
  • 2025-05-09: patched: Vendor released version 019.005.000.000
  • 2025-08-25: advisory: Third-party advisory published by usd HeroLab
  • 2025-09-08: advisory: CVE published to NVD

References