CVE-2025-6735: juzaweb CMS Import Page imports improper authorization
A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6735?
CVE-2025-6735 is classified as a critical vulnerability in juzaweb CMS 3.4.2.
How do I fix CVE-2025-6735?
To fix CVE-2025-6735, it is recommended to update to the latest version of juzaweb CMS that addresses this vulnerability.
What component is affected by CVE-2025-6735?
CVE-2025-6735 affects the Import Page component of the juzaweb CMS.
Can CVE-2025-6735 be exploited remotely?
Yes, CVE-2025-6735 can be exploited remotely due to improper authorization in the affected component.
What is the nature of the vulnerability in CVE-2025-6735?
CVE-2025-6735 involves improper authorization, allowing unauthorized actions within juzaweb CMS.