A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-25T00:00:00.000Z
Updated: 2025-11-25T15:51:09.606Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64050
Updated: 2025-11-25T15:50:25.250Z
Status : Awaiting Analysis
Published: 2025-11-25T16:16:07.430
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-64050
No data.