← Back

CVE-2025-64050

nvd nist
Published: Nov 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

Affected (1)

Products: Redaxo: Redaxo
1 product
Redaxo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.20.0

Timeline

No history available yet.