Broken Access Control Vulnerability in Juzaweb CMS
CVE-2025-5429
Key Information:
Badges
What is CVE-2025-5429?
A vulnerability affecting Juzaweb CMS prior to version 3.4.2 has been identified, specifically in the /admin-cp/plugin/install section of the Plugins Page. This flaw allows for improper access controls, which can enable attackers to manipulate certain functionalities remotely. The exploit has been publicly disclosed, raising concerns for users of this CMS. Although the vendor was notified prior to public disclosure, there was no response, highlighting the urgency for affected users to assess their system's security and implement necessary mitigations.
Affected Version(s)
CMS 3.4.0
CMS 3.4.1
CMS 3.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.