CVE-2025-5428: juzaweb CMS Error Logs Page log-viewer access control
A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of the component Error Logs Page. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5428?
CVE-2025-5428 is classified as critical due to improper access controls in the Juzaweb CMS.
How can I mitigate CVE-2025-5428?
To mitigate CVE-2025-5428, upgrade Juzaweb CMS to the latest version beyond 3.4.2.
What components are affected by CVE-2025-5428?
CVE-2025-5428 affects the Error Logs Page component located at /admin-cp/log-viewer in Juzaweb CMS.
Is CVE-2025-5428 exploitable remotely?
Yes, CVE-2025-5428 can be exploited remotely due to the nature of the vulnerability.
What are the consequences of CVE-2025-5428 if exploited?
Exploitation of CVE-2025-5428 can lead to unauthorized access to sensitive error log data.