PT-2025-54416 · Unknown · Kohana Kodicms
Hiro
·
Published
2025-12-31
·
Updated
2025-12-31
·
CVE-2025-15392
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kohana KodiCMS versions through 13.82.135
Description
A flaw exists in Kohana KodiCMS that could allow for remote code execution. The issue stems from the manipulation of the
keyword argument within the like function located in the file cms/modules/pages/classes/kodicms/model/page.php, specifically within the Search API Endpoint. This can lead to SQL injection. The exploit for this issue is publicly available. The vendor was notified but did not respond.Recommendations
Versions prior to 13.82.135 should be used. As a temporary workaround, consider restricting access to the Search API Endpoint until a patch is available.
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kohana Kodicms