CVE-2026-19975

Summary

A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.

Affected Software

VendorProductVersion RangeStatus
AzuriomCMS1.2.0affected
AzuriomCMS1.2.1affected
AzuriomCMS1.2.2affected
AzuriomCMS1.2.3affected
AzuriomCMS1.2.4affected
AzuriomCMS1.2.5affected
AzuriomCMS1.2.6affected
AzuriomCMS1.2.7affected
AzuriomCMS1.2.8affected
AzuriomCMS1.2.9affected
AzuriomCMS1.2.10affected
AzuriomCMS1.2.11affected
AzuriomCMS1.2.12affected
AzuriomCMS1.2.13unaffected

Weaknesses

  • CWE-367: Time-of-check Time-of-use
  • CWE-362: Race Condition

References