logo

Technical Advisory: Condeon CMS

ID: 81c611fd-c354-5c9a-8ffb-c98202d6c81c

STIX ID: report--81c611fd-c354-5c9a-8ffb-c98202d6c81c

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2025-07-28

Date Updated: 2026-08-03

ADMIRALTY:B6
...
...

Vioma's Condeon CMS versions <= 1.9.1 contain two critical issues: a publicly exposed memory dump (CVE-2025-44202) that leaks sensitive server data and session cookies, and a mass-assignment vulnerability (CVE-2025-44200) that allows authenticated users to change CustomerID values and obtain administrative access across hosted tenants; together these enable reliable cross-customer takeover. Vioma acknowledged the issues and released patches in version 1.9.2 on 2025-06-05.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.