Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure. | |
| Title | Azuriom CMS Money Transfer ProfileController.php transferMoney toctou | |
| First Time appeared |
Azuriom
Azuriom cms |
|
| Weaknesses | CWE-362 CWE-367 |
|
| CPEs | cpe:2.3:a:azuriom:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuriom
Azuriom cms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-17T02:30:10.701Z
Reserved: 2026-08-16T08:56:10.076Z
Link: CVE-2026-19975
No data.
Status : Received
Published: 2026-08-17T03:16:50.143
Modified: 2026-08-17T03:16:50.143
Link: CVE-2026-19975
No data.
OpenCVE Enrichment
Updated: 2026-08-17T06:45:03Z