CVE-2025-5423: juzaweb CMS General Setting Page general access control
A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/setting/system/general of the component General Setting Page. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5423?
CVE-2025-5423 is classified as a critical vulnerability.
How does CVE-2025-5423 affect juzaweb CMS?
CVE-2025-5423 affects the General Setting Page in juzaweb CMS versions up to 3.4.2.
What type of vulnerability is CVE-2025-5423?
CVE-2025-5423 is related to improper access controls.
How can I mitigate CVE-2025-5423?
To mitigate CVE-2025-5423, upgrade juzaweb CMS to a version beyond 3.4.2.
What specifically can be exploited in CVE-2025-5423?
CVE-2025-5423 allows unauthorized access to the settings in the administration panel.