VYPR
Unrated severityOSV Advisory· Published Dec 8, 2025· Updated Dec 11, 2025

CVE-2025-65271

CVE-2025-65271

Description

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Azuriom/AzuriomOSV2 versions
    0.2.4, v0.1, v0.1.1, …+ 1 more
    • (no CPE)range: 0.2.4, v0.1, v0.1.1, …
    • (no CPE)range: <1.2.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.