CVE-2025-61505 | e107 CMS up to 2.3.3 POST Parameter install.php base64_decode previous_steps deserialization
A vulnerability described as critical has been identified in e107 CMS up to 2.3.3. Impacted is the function base64_decode of the file install.php of the component POST Parameter Handler. The manipulation of the argument previous_steps results in deserialization.
This vulnerability was named CVE-2025-61505. The attack may be performed from remote. There is no available exploit.