CVE-2025-5420 | juzaweb CMS up to 3.4.2 Profile Page upload Upload cross site scripting
A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/file-manager/upload of the component Profile Page. The manipulation of the argument Upload leads to cross site scripting.
This vulnerability is known as CVE-2025-5420. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.