PT-2025-49587 · Unknown · Azuriom Cms

Published

2025-12-08

·

Updated

2025-12-09

·

CVE-2025-65271

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azuriom CMS versions prior to 1.2.7
Description A client-side template injection (CSTI) issue exists in the Azuriom CMS admin dashboard. A low-privilege user can execute arbitrary template code within the context of an administrator's session. This is possible through plugins or dashboard components that render untrusted user input, potentially leading to privilege escalation. The vulnerable components render untrusted user input without proper sanitization.
Recommendations Update to Azuriom CMS version 1.2.7 or later.

Exploit

Fix

LPE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-65271

Affected Products

Azuriom Cms