CVE-2025-63523

MEDIUM6.5EPSS 0.05%

FeehiCMS fails to enforce server-side immutability

Published: 12/1/2025Modified: 12/2/2025
Also known as:GHSA-qgc9-p7cj-jvh6

Description

FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References (4)