Improper Access Control in Juzaweb CMS Theme Editor Page
CVE-2025-5425
5.3MEDIUM
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-5425?
A vulnerability exists in Juzaweb CMS up to version 3.4.2, specifically within the Theme Editor Page component. This flaw allows unauthorized users to manipulate access controls inappropriately, which can lead to unauthorized actions within the CMS. The exploitation of this vulnerability can be performed remotely, posing a significant risk as it may be leveraged by attackers to gain unauthorized access. Despite early warnings to the vendor, no response was received regarding this critical issue.
Affected Version(s)
CMS 3.4.0
CMS 3.4.1
CMS 3.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.