CVE-2025-5425: juzaweb CMS Theme Editor Page default access control
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor Page. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5425?
CVE-2025-5425 is classified as a critical vulnerability.
How do I fix CVE-2025-5425?
To fix CVE-2025-5425, upgrade juzaweb CMS to version 3.4.3 or later.
What components are affected by CVE-2025-5425?
CVE-2025-5425 affects the Theme Editor Page component in juzaweb CMS.
What type of access control issue is present in CVE-2025-5425?
CVE-2025-5425 leads to improper access controls in the affected component.
Can CVE-2025-5425 allow unauthorized access?
Yes, CVE-2025-5425 has the potential to allow unauthorized access due to improper access controls.