CVE-2025-67165
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/12/2025
Last modified:
18/12/2025
Description
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67165
- https://github.com/pagekit/docs/blob/develop/user-interface/users.md#permissions
- https://github.com/pagekit/docs/blob/develop/user-interface/users.md#roles
- https://github.com/pagekit/pagekit
- https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67165



