Home

Description

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-08 | Updated 2025-12-11 | Assigner mitre

References

github.com/1337Skid/CVE-2025-65271 exploit

github.com/Azuriom/Azuriom

www.github.com/Azuriom/Azuriom

github.com/...ommit/0289175547319add814dcb526e8ba034f1ebc3ec

www.github.com/...t/0289175547319add814dcb526e8ba034f1ebc3ec

github.com/1337Skid/CVE-2025-65271

cve.org (CVE-2025-65271)

nvd.nist.gov (CVE-2025-65271)

Download JSON