PT-2026-73194 · Unknown · Azuriom Cms
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Azuriom CMS versions prior to 1.2.13
Description
A time-of-check time-of-use (TOCTOU) issue exists in the Money Transfer Handler component. This occurs within the
transferMoney() function located in the app/Http/Controllers/ProfileController.php file. A remote attacker can exploit this weakness, although the attack requires a high degree of complexity and is considered difficult to execute. TOCTOU is a race condition where a system checks the state of a resource before using it, but the state changes between the check and the use.Recommendations
Update to version 1.2.13.
As a temporary mitigation, restrict access to the
transferMoney() function until the update is applied.Exploit
Fix
Time Of Check To Time Of Use
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azuriom Cms