CVE-2026-19975 | Azuriom CMS up to 1.2.12 Money Transfer ProfileController.php transferMoney toctou
A vulnerability was found in Azuriom CMS up to 1.2.12. It has been rated as critical. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use.
This vulnerability appears as CVE-2026-19975. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is advised.
The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More