CVE-2020-25538: Cmsuno Project Cmsuno

High severity, CVSS 8.8. EPSS: 10% chance of exploitation in the next 30 days.

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

Affected products

Published 2020-11-13. Last modified 2026-06-17.