Medium severity6.5OSV Advisory· Published Dec 1, 2025· Updated Jun 17, 2026
CVE-2025-63523
CVE-2025-63523
Description
FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- ghsa-coords
Patches
Vulnerability mechanics
References
4- github.com/kiwi865/CVEs/blob/main/CVE-2025-63523.mdnvdExploitThird Party AdvisoryWEB
- github.com/liufee/cms/issues/77nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-qgc9-p7cj-jvh6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-63523ghsaADVISORY
News mentions
0No linked articles in our index yet.