5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2025-14729
Source
VulDB
Published
Dec 15, 2025 at 23:02
Affected Product
Vendor
CTCMS
Product
Content Management System
Version
2.1.0
Affected Versions
CTCMS Content Management System 2.1.0
CTCMS Content Management System 2.1.1
CTCMS Content Management System 2.1.2
CTCMS Content Management System 2.1.1
CTCMS Content Management System 2.1.2