5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
Basic Information
ID
CVE-2025-14730
Source
VulDB
Published
Dec 15, 2025 at 23:02
Affected Product
Vendor
CTCMS
Product
Content Management System
Version
2.1.0
Affected Versions
CTCMS Content Management System 2.1.0
CTCMS Content Management System 2.1.1
CTCMS Content Management System 2.1.2
CTCMS Content Management System 2.1.1
CTCMS Content Management System 2.1.2