CVE-2025-64050: Code Injection
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64050?
CVE-2025-64050 is classified as a high severity Remote Code Execution vulnerability.
How do I fix CVE-2025-64050?
To remediate CVE-2025-64050, upgrade your REDAXO CMS installation to version 5.20.1 or later.
Who is affected by CVE-2025-64050?
CVE-2025-64050 affects remote authenticated administrators of REDAXO CMS version 5.20.0.
What can an attacker do with CVE-2025-64050?
An attacker can execute arbitrary operating system commands by injecting PHP code into an active template.
When was CVE-2025-64050 disclosed?
CVE-2025-64050 was disclosed in 2025, following the identification of the vulnerability in REDAXO CMS.