Server-Side Immutability Flaw in FeehiCMS by liufee
CVE-2025-63523
6.5MEDIUM
What is CVE-2025-63523?
FeehiCMS version 2.1.1 is vulnerable due to a failure to enforce server-side immutability for parameters labeled as 'read-only.' This vulnerability enables authenticated attackers to intercept these parameters during transmission and manipulate them. As a result, the backend system may accept the modified parameters, leading to unauthorized changes such as unintended username alterations. This exposure can compromise application integrity and potentially lead to further security risks.
