CVE-2025-66571 | UNA CMS up to 14.0.0-RC4 POST Parameter BxBaseMenuSetAclLevel.php unserialize profile_id deserialization (Exploit 52139 / EDB-52139)
A vulnerability marked as critical has been reported in UNA CMS up to 14.0.0-RC4. The affected element is the function unserialize of the file BxBaseMenuSetAclLevel.php of the component POST Parameter Handler. The manipulation of the argument profile_id leads to deserialization.
This vulnerability is listed as CVE-2025-66571. The attack may be initiated remotely. In addition, an exploit is available.