TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-15393

MEDIUM
6.3

Beschreibung

A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the argument content leads to code injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE Details

CVSS v3.1 Bewertung6.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht12/31/2025
Zuletzt geandert1/5/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

kodicms-kohana:kodicms

Schwachen (CWE)

CWE-74CWE-94CWE-94

Referenzen

https://vuldb.com/?submit.718290(134c704f-9b21-4f2e-91b3-4a467353bcc0)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.