CVE-2025-15148 | CmsEasy up to 7.7.7 Backend Template Management Page template_admin.php savetemp_action content/tempdata code injection (EUVD-2025-205522)
A vulnerability was found in CmsEasy up to 7.7.7 and classified as critical. Affected is the function savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Page. Executing manipulation of the argument content/tempdata can lead to code injection.
The identification of this vulnerability is CVE-2025-15148. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.