CVE-2025-0465
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 502
CWE ID 20
Summary
CVE-2025-0465 is a critical vulnerability affecting AquilaCMS version 1.412.13. The issue lies within an unknown functionality of the /api/v2/categories file. The manipulation of the PostBody.populate argument triggers deserialization, which can be exploited remotely. The public disclosure of the exploit increases the risk for attacks. Despite early notification, the vendor has not responded to address the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.