CNNVD-202512-5701 Information

CNNVD ID

CNNVD-202512-5701

CVE-2025-15374

  • CNNVD Published: 2025-12-31

Description (Chinese)

EyouCMS是中国易优(Eyou)公司的一套基于ThinkPHP的开源内容管理系统(CMS)。 EyouCMS 1.7.7及之前版本存在跨站脚本漏洞,该漏洞源于对文件application/home/model/Ask.php中参数content的错误操作,可能导致跨站脚本攻击。

Description (English)

EyouCMS is an open-source content management system (CMS) based on ThinkPHP for Eyou. EyouCMS 1.7.7 and previous versions contain a cross-site script loophole, which stems from an error in the application/home/mode/Ask.php parameter content, which may result in a cross-site script attack.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

易优

Published

2025-12-31

Last Modified

2026-02-24

References

https://vuldb.com/?submit.718480 https://note-hxlab.wetolink.com/share/LNickWiRaFiF#-span–strong-proof-of-concept—strong—span- https://vuldb.com/?id.339082 https://vuldb.com/?ctiid.339082

Patch

https://www.eyoucms.com/rizhi/

Share on: