CVE-2025-5422: juzaweb CMS Email Logs Page email access control
A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/logs/email of the component Email Logs Page. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5422?
CVE-2025-5422 is classified as problematic, indicating a significant security risk in juzaweb CMS up to version 3.4.2.
How do I fix CVE-2025-5422?
To fix CVE-2025-5422, upgrade to a version of juzaweb CMS that is higher than 3.4.2, ensuring the proper access controls are implemented.
What component of juzaweb CMS is affected by CVE-2025-5422?
CVE-2025-5422 affects the Email Logs Page component, specifically the /admin-cp/logs/email file.
Can CVE-2025-5422 be exploited remotely?
Yes, CVE-2025-5422 can be exploited remotely due to improper access controls.
Who is affected by CVE-2025-5422?
Users and administrators of juzaweb CMS versions up to 3.4.2 are affected by CVE-2025-5422.