CVE-2025-5420: juzaweb CMS Profile Page upload cross site scripting
A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/file-manager/upload of the component Profile Page. The manipulation of the argument Upload leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5420?
CVE-2025-5420 is classified as a problematic vulnerability due to its potential for cross site scripting (XSS).
How can I fix CVE-2025-5420?
To fix CVE-2025-5420, upgrade Juzaweb CMS to version 3.4.3 or later, which addresses the vulnerability in the file manager component.
What versions of Juzaweb CMS are affected by CVE-2025-5420?
Juzaweb CMS versions up to and including 3.4.2 are affected by CVE-2025-5420.
What component is vulnerable in CVE-2025-5420?
The vulnerable component in CVE-2025-5420 is the file upload functionality of the Profile Page within the admin panel.
What does CVE-2025-5420 exploit?
CVE-2025-5420 exploits a cross site scripting vulnerability through manipulated upload arguments in the file manager.