PT-2025-51846 · Unknown · Pagekit Cms
Mbiesiad
·
Published
2025-12-17
·
Updated
2026-01-02
·
CVE-2025-67165
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pagekit CMS version 1.0.18
Description
An Insecure Direct Object Reference (IDOR) exists in Pagekit CMS version 1.0.18, potentially allowing attackers to escalate privileges. An IDOR occurs when an application uses user-supplied input to directly access objects, leading to unauthorized access. In this instance, an attacker could potentially manipulate object references to gain elevated privileges within the system. The API endpoint is not specified. The vulnerable parameter is not specified. The vulnerable function is not specified.
Recommendations
Update Pagekit CMS to a version that addresses this issue. As a temporary workaround, implement stricter access controls and validation of object references to prevent unauthorized access.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pagekit Cms