Time-of-Check Time-of-Use Vulnerability in Azuriom CMS Money Transfer Function
CVE-2026-19975
2.3LOW
What is CVE-2026-19975?
A vulnerability has been discovered in Azuriom CMS versions up to 1.2.12, affecting the money transfer functionality in the ProfileController. This weakness allows a remote attacker to manipulate the time-of-check time-of-use condition, potentially leading to unauthorized financial operations. The complexity of exploitation is high, requiring specific conditions to be met. Users are encouraged to upgrade to version 1.2.13, which includes a patch to mitigate this vulnerability. For further security, following best practices in application management and regularly updating systems is recommended.
Affected Version(s)
CMS 1.2.0
CMS 1.2.1
CMS 1.2.2
