Code Injection Vulnerability in 08CMS Novel System by 08CMS
CVE-2025-15250
Key Information:
- Vendor
08cms
- Status
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2025-15250?
A security flaw has been identified in the 08CMS Novel System, where certain processing within the admina/mtpls.inc.php file of the Template Handler component allows for code injection. This vulnerability enables attackers to execute code remotely, potentially compromising the system. The details of the exploit have been made public, raising concerns about its exploitation in the wild. Users are advised to implement necessary security measures to mitigate risk.
Affected Version(s)
Novel System 3.0
Novel System 3.1
Novel System 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
