Insecure Direct Object Reference in Pagekit CMS Affects User Privilege Management
CVE-2025-67165

9.8CRITICAL

Key Information:

Vendor

Pagekit

Vendor
CVE Published:
17 December 2025

What is CVE-2025-67165?

The Pagekit CMS version 1.0.18 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability, which could allow unauthorized users to escalate their privileges. This weakness potentially permits attackers to access or modify user roles and permissions, compromising the integrity of the platform and exposing sensitive data. Ensuring the proper validation of user requests and implementing robust access controls can help mitigate such vulnerabilities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.