CVE-2026-19975 PUBLISHED

Azuriom CMS Money Transfer ProfileController.php transferMoney toctou

Assigner: VulDB
Reserved: 16.08.2026 Published: 17.08.2026 Updated: 17.08.2026

A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 2.3

Product Status

Vendor Azuriom
Product CMS
Versions
  • Version 1.2.0 is affected
  • Version 1.2.1 is affected
  • Version 1.2.2 is affected
  • Version 1.2.3 is affected
  • Version 1.2.4 is affected
  • Version 1.2.5 is affected
  • Version 1.2.6 is affected
  • Version 1.2.7 is affected
  • Version 1.2.8 is affected
  • Version 1.2.9 is affected
  • Version 1.2.10 is affected
  • Version 1.2.11 is affected
  • Version 1.2.12 is affected
  • Version 1.2.13 is unaffected

Credits

  • javiertzr01 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Time-of-check Time-of-use CWE
  • Race Condition CWE