CVE-2025-0465 is a critical deserialization vulnerability affecting AquilaCMS version 1.412.13, specifically within the /api/v2/categories file when manipulating the PostBody.populate argument. This vulnerability has a CVSS score of 7.3 (High), indicating it can be exploited remotely with low attack complexity, potentially leading to low impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed and the vendor has not responded, there is currently no evidence of active exploitation, nor are there readily available exploit modules in common frameworks or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | AquilaCMS | 1.412.13CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.