Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14731

Опубликовано: 16 дек. 2025
Источник: nvd
CVSS3: 6.3
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ctcms_project:ctcms:*:*:*:*:*:*:*:*
Версия до 2.1.2 (включая)

EPSS

Процентиль: 19%
0.00061
Низкий

6.3 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-791

Связанные уязвимости

CVSS3: 6.3
github
около 2 месяцев назад

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

EPSS

Процентиль: 19%
0.00061
Низкий

6.3 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-791