savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Page. Executing manipulation of the argument content/tempdata can lead to code injection.
The identification of this vulnerability is CVE-2025-15148. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Intelligence View
SOCIAL SHARE CARD GENERATOR