Description

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.

INFO

Published Date :

2025-12-08T00:00:00.000Z

Last Modified :

2025-12-11T14:37:05.722Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-65271 vulnerability.

Vendors Products
Azuriom
  • Azuriom

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact