CNNVD-202512-5698 Information
Dec 31, 2025
cve
CNNVD ID
CNNVD-202512-5698
Related CVE
- CNNVD Published: 2025-12-31
Description (Chinese)
EyouCMS是中国易优(Eyou)公司的一套基于ThinkPHP的开源内容管理系统(CMS)。 EyouCMS 1.7.7及之前版本存在安全漏洞,该漏洞源于对文件application/function.php中函数saveRemote的错误操作,可能导致服务端请求伪造。
Description (English)
EyouCMS is an open-source content management system (CMS) based on ThinkPHP for Eyou. EyouCMS 1.7.7 and previous versions contain a security loophole, which stems from an error in the application/faction.php function saveRemote, which may lead to the forgery of service requests.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
易优
Published
2025-12-31
Last Modified
2026-02-24
References
https://note-hxlab.wetolink.com/share/DeUFyoSjsPPK https://note-hxlab.wetolink.com/share/DeUFyoSjsPPK#-span–strong-proof-of-concept—strong—span- https://vuldb.com/?ctiid.339081 https://vuldb.com/?id.339081 https://vuldb.com/?submit.718465
Patch
https://www.eyoucms.com/rizhi/
Share on: