PT-2025-45594 · Cybertutor · New Site Server

Published

2025-11-10

·

Updated

2025-11-14

·

CVE-2025-12868

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions New Site Server (affected versions not specified)
Description New Site Server, developed by CyberTutor, is affected by a Use of Client-Side Authentication issue. This allows unauthenticated remote attackers to modify the frontend code, potentially gaining administrator privileges on the website. The modification of frontend code enables attackers to bypass authentication controls and achieve complete control over the website’s administrative functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-12868

Affected Products

New Site Server