CVE-2025-65271 is a client-side template injection (CSTI) vulnerability in the Azuriom CMS admin dashboard. The vulnerability allows a low-privilege user to inject and execute arbitrary template code in the context of an administrator's session. This is possible through plugins or dashboard components that render untrusted user input without proper sanitization. Successful exploitation can lead to privilege escalation, allowing the attacker to gain administrative access. The issue is fixed in Azuriom version 1.2.7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-65271, a client-side template injection (CSTI) vulnerability in Azuriom CMS (fixed in version 1.2.7). The exploit consists of two main code files: - `payload.js`: JavaScript code designed to be executed in the context of an administrator's browser session. It fetches the CSRF token from the admin users page and submits a POST request to create a new admin user ('poc_pwned'). - `server.js`: A simple Node.js HTTP server that serves `payload.js` as `/a.js` on port 1234. This allows the attacker to host the payload and have it fetched and executed via a template injection vector in the admin dashboard. The attack vector is browser-based, relying on the ability to inject a template payload that causes the admin's browser to fetch and execute the attacker's JavaScript. The exploit targets the internal admin endpoint (`http://192.168.0.24/admin/users`) and requires the attacker to be able to inject code into the admin dashboard (e.g., via plugins or dashboard components). The result is privilege escalation by creating a new admin user. The repository is structured as a minimal PoC, with clear separation between the payload and the server used to deliver it.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.