A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Nov 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redaxo
Redaxo redaxo Redaxo redaxo Cms |
|
| Vendors & Products |
Redaxo
Redaxo redaxo Redaxo redaxo Cms |
Tue, 25 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-25T00:00:00.000Z
Updated: 2025-11-25T15:51:09.606Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64050
Updated: 2025-11-25T15:50:25.250Z
Status : Awaiting Analysis
Published: 2025-11-25T16:16:07.430
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-64050
No data.