CVE-2025-64050

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-25 16:16

Updated : 2025-12-03 17:06


NVD link : CVE-2025-64050

Mitre link : CVE-2025-64050

CVE.ORG link : CVE-2025-64050


JSON object : View

Products Affected

redaxo

  • redaxo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')