
PoC for CVE-2025-65271 | Found by me
PoC for CVE-2025-65271
node server.js
Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7
I am not responsible for any actions taken by others using this PoC. I have provided it for research and security testing purposes only. I explicitly discourage any illegal or unethical use including unauthorized hacking or exploitation of systems. Use at your own risk and in compliance with applicable laws.
Do not ask on how to get a RCE using this PoC, I've provided this PoC for security measures only and to show the impact of the vulnerability