CVE-2025-65854
CRITICAL9.8EPSS 0.09%MineAdmin has an insecure default password
Published: 12/12/2025Modified: 12/12/2025
Also known as:GHSA-x6mh-4w8x-p34v
Description
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.
Affected packages (1)
- Packagist/mineadmin/mineadminfrom 0, <= 3.0.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-65854
- PATCHhttps://github.com/mineadmin/mineadmin
- WEBhttp://mineadmin.com
- WEBhttps://gist.github.com/SourByte05/1a6c6b08ac47c5d58eb7dd4422cc23b7
- WEBhttps://github.com/mineadmin/mine-core/blob/7994da7f5cd0778eb9aadd550c50c259cc1d1048/src/Command/InstallProjectCommand.php#L123