CVE-2025-62369

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*

History

08 Dec 2025, 13:30

Type Values Removed Values Added
First Time Xibosignage
Xibosignage xibo
CPE cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*
References () https://github.com/xibosignage/xibo-cms/commit/0f4e88396111ea027785a48dd8f5eeb14536bd71 - () https://github.com/xibosignage/xibo-cms/commit/0f4e88396111ea027785a48dd8f5eeb14536bd71 - Patch
References () https://github.com/xibosignage/xibo-cms/commit/ecd4f9d2cea739a46756a108a839cac80f65cf10 - () https://github.com/xibosignage/xibo-cms/commit/ecd4f9d2cea739a46756a108a839cac80f65cf10 - Patch
References () https://github.com/xibosignage/xibo-cms/releases/tag/4.3.1 - () https://github.com/xibosignage/xibo-cms/releases/tag/4.3.1 - Release Notes
References () https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-7rmm-689c-gjgv - () https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-7rmm-689c-gjgv - Third Party Advisory
References () https://patch-diff.githubusercontent.com/raw/xibosignage/xibo-cms/pull/3128.patch - () https://patch-diff.githubusercontent.com/raw/xibosignage/xibo-cms/pull/3128.patch - Product

04 Nov 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 22:16

Updated : 2025-12-08 13:30


NVD link : CVE-2025-62369

Mitre link : CVE-2025-62369

CVE.ORG link : CVE-2025-62369


JSON object : View

Products Affected

xibosignage

  • xibo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine