file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. Executing a manipulation of the argument cpage_custom can lead to deserialization.This vulnerability is tracked as CVE-2025-5498. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
SOCIAL SHARE CARD GENERATOR