CVE-2025-64050 Details
Description
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
A remote code execution vulnerability has been identified in REDAXO CMS version 5.20.0. This issue arises in the template management component, where remote authenticated administrators can execute arbitrary operating system commands. The vulnerability is exploited by injecting PHP code into an active template, with the payload being executed when visitors access frontend pages that use the compromised template.
Users are advised to update to REDAXO CMS version 5.20.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/drive/folders/1Via4r4wn5zCcBllWmHpxYweCPgcbN0bz?usp=sharing | [email protected] | Exploit |
| https://github.com/redaxo/redaxo | [email protected] | Product |
| https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64050.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redaxo redaxo | 5.20.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 3, 2025 | Initial Analysis | [email protected] |
| Nov 25, 2025 | New CVE Received | [email protected] |
| Nov 25, 2025 | CVE Modified | CISA-ADP |