Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19247 | JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing certain components |
Github GHSA |
GHSA-mrph-pjv2-34f4 | JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing certain components |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Juzaweb
Juzaweb cms |
|
| CPEs | cpe:2.3:a:juzaweb:cms:3.4.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Juzaweb
Juzaweb cms |
Fri, 27 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Jun 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the component Add New Themes Page. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | juzaweb CMS Add New Themes Page install improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-27T14:15:48.513Z
Reserved: 2025-06-26T16:04:18.300Z
Link: CVE-2025-6736
Updated: 2025-06-27T14:15:36.663Z
Status : Analyzed
Published: 2025-06-27T00:15:38.790
Modified: 2025-07-11T14:22:16.897
Link: CVE-2025-6736
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:32Z
EUVD
Github GHSA