CNNVD-202512-2622 Information

CNNVD ID

CNNVD-202512-2622

CVE-2025-14722

  • CNNVD Published: 2025-12-15

Description (Chinese)

DMadmin是中国vion707开源的一个基础接口框架。 DMadmin存在代码注入漏洞,该漏洞源于文件Admin/Controller/AddonsController.class.php中Add函数存在跨站脚本漏洞,可被远程利用。

Description (English)

DMadmin is a basic interface framework for the vion707 open source in China. DMadmin has a code-in-the-code loophole, which stems from the fact that the Add function in document Admin/Controller/AddonsController.class.php has a cross-site script loophole that can be used remotely.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

vion707

Published

2025-12-15

Last Modified

2026-02-24

References

https://vuldb.com/?submit.707130 https://github.com/DeepMountains/zzz/blob/main/CVE-2025-2-2.md https://vuldb.com/?id.336467 https://vuldb.com/?ctiid.336467 https://access.redhat.com/security/cve/cve-2025-14722

Share on: