CNNVD-202508-393 Information

CNNVD ID

CNNVD-202508-393

CVE-2025-52237

  • CNNVD Published: 2025-08-05

Description (Chinese)

SSCMS(SiteServerCMS)是中国百容千域(SSCMS)公司的一个内容管理系统。 SSCMS(SiteServerCMS) v7.3.1版本存在安全漏洞,该漏洞源于组件/stl/actions/download?filePath存在目录遍历漏洞。

Description (English)

SSCMS (SiteServerCMS) is a content management system of China’s Centauri Corporation. The SSCMS (SiteServerCMS) v7.3.1 has a security loophole, which stems from the existence of a directory of a component/stl/actions/download?filePath.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

百容千域

Published

2025-08-05

Last Modified

2026-02-24

References

https://gist.github.com/CTRLCCT/c9b5aab78a179a2d92a41889a588c933 http://sscms.com https://access.redhat.com/security/cve/cve-2025-52237

Share on: