A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to deserialization.
This vulnerability is known as CVE-2025-7099. The attack can be launched remotely. Furthermore, there is an exploit available.