Description
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
Published: 2026-06-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SEMCMS version 5.0 has a flaw in the file SEMCMS_copy.php that allows a user to access the script without proper authorization. The vulnerability results in an authentication bypass, permitting any user who can reach the PHP file to view or use its functionality regardless of intended security controls. The impact is the loss of confidentiality and potential availability of restricted functions, as the code may expose sensitive data or enable further exploitation if the script can be invoked by an attacker.

Affected Systems

The affected product is SEMCMS 5.0. No other vendors or versions are listed in the advisory, and no detailed version range is available. Systems running SEMCMS 5.0 should be verified for the presence of the file SEMCMS_copy.php and the lack of authentication checks.

Risk and Exploitability

No EPSS score is provided, and the vulnerability is not listed in CISA KEV, so the current exploitation probability is unknown. However, the nature of the flaw—unauthorized access to a PHP script—indicates that an attacker could potentially reach the file over the web if the server serves it, making exploitation relatively straightforward if the file contains sensitive logic. The severity of the flaw depends on what functionality the script provides, but the lack of access controls creates an opportunity for privilege escalation or data exposure. The vulnerability is likely exploitable via a direct HTTP request to the file path.

Generated by OpenCVE AI on June 9, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Move or delete SEMCMS_copy.php from the web root to eliminate public access
  • Apply any vendor‑released patch or updated version of SEMCMS that addresses authentication checks for this script
  • Configure file system permissions so that only trusted users can read or execute SEMCMS_copy.php and ensure the web server does not serve it via publicly accessible URLs

Generated by OpenCVE AI on June 9, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via SEMCMS_copy.php in SEMCMS 5.0
Weaknesses CWE-285

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T19:39:02.349Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39169

cve-icon Vulnrichment

Updated: 2026-06-09T19:38:43.782Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:17:48.183

Modified: 2026-06-09T21:17:11.650

Link: CVE-2026-39169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T21:45:05Z

Weaknesses