Skip to main content

Incorrect Privilege Assignment

CVE-2025-6736

Severity Low
Score 2.1/10

Summary

A vulnerability has been found in juzaweb CMS. Affected is an unknown function of the file "/admin-cp/theme/install" of the component Add New Themes Page. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-266 - Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Advisory Timeline

  • Published