CVE-2026-19975: Azuriom CMS Money Transfer ProfileController.php transferMoney toctou
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Azuriom CMSto a version that resolves this vulnerability.Fixed in 1.2.13Patch ae5596a9548e010a8a79838806eff60ef9554539 - Upgrade
Upgrade
Azuriom CMS (Money Transfer Handler / app/Http/Controllers/ProfileController.php - transferMoney)to a version that resolves this vulnerability.Fixed in 1.2.13Patch ae5596a9548e010a8a79838806eff60ef9554539
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19975?
The severity of CVE-2026-19975 is low with a score of 3.1.
How do I fix CVE-2026-19975?
To address CVE-2026-19975, you should update Azuriom CMS to version 1.2.13 or later.
What type of vulnerability is CVE-2026-19975?
CVE-2026-19975 is categorized as a Race Condition vulnerability.
Can CVE-2026-19975 be exploited remotely?
Yes, CVE-2026-19975 can be exploited remotely.
What components are affected by CVE-2026-19975?
CVE-2026-19975 affects the transferMoney function in the ProfileController.php file of the Money Transfer Handler.