CVE-2026-19975
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Summary
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Azuriom | CMS | 1.2.0 | affected |
| Azuriom | CMS | 1.2.1 | affected |
| Azuriom | CMS | 1.2.2 | affected |
| Azuriom | CMS | 1.2.3 | affected |
| Azuriom | CMS | 1.2.4 | affected |
| Azuriom | CMS | 1.2.5 | affected |
| Azuriom | CMS | 1.2.6 | affected |
| Azuriom | CMS | 1.2.7 | affected |
| Azuriom | CMS | 1.2.8 | affected |
| Azuriom | CMS | 1.2.9 | affected |
| Azuriom | CMS | 1.2.10 | affected |
| Azuriom | CMS | 1.2.11 | affected |
| Azuriom | CMS | 1.2.12 | affected |
| Azuriom | CMS | 1.2.13 | unaffected |
Weaknesses
- CWE-367: Time-of-check Time-of-use
- CWE-362: Race Condition
References
- https://vuldb.com/vuln/391154
- https://vuldb.com/vuln/391154/cti
- https://vuldb.com/cve/CVE-2026-19975
- https://vuldb.com/submit/873734
- https://github.com/Azuriom/Azuriom/commit/ae5596a9548e010a8a79838806eff60ef9554539
- https://github.com/Azuriom/Azuriom/releases/tag/v1.2.13
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.