A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 25 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Lmxcms
Lmxcms lmxcms
CPEs cpe:2.3:a:lmxcms:lmxcms:1.41:*:*:*:*:*:*:*
Vendors & Products Lmxcms
Lmxcms lmxcms

Wed, 19 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title lmxcms Maintenance db.inc.php code injection
Weaknesses CWE-74
CWE-94
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:N/AC:H/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-02-19T15:31:05.020Z

Updated: 2025-02-19T16:23:26.787Z

Reserved: 2025-02-19T06:38:06.254Z

Link: CVE-2025-1465

cve-icon Vulnrichment

Updated: 2025-02-19T16:14:12.720Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-19T16:15:40.667

Modified: 2025-02-25T21:07:23.137

Link: CVE-2025-1465

cve-icon Redhat

No data.