CVE-2025-15374
MEDIUM
5,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
MEDIUM
4,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: partial
Availability: none
Description
AI Translation Available
A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing a manipulation of the argument content results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor is '[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8'.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0003
Percentile
0,1th
Updated
EPSS Score Trend (Last 76 Days)
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
94
Improper Control of Generation of Code ('Code Injection')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Non-Repudiation
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Hide Activities
Applicable Platforms
Languages:
Interpreted
Technologies:
AI/ML
Application
Eyoucms by Eyoucms
Version Range Affected
To
1.7.8
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://note-hxlab.wetolink.com/share/LNickWiRaFiF
https://note-hxlab.wetolink.com/share/LNickWiRaFiF#-span--strong-proof-of-conce…
https://note-hxlab.wetolink.com/share/LNickWiRaFiF
https://note-hxlab.wetolink.com/share/LNickWiRaFiF#-span--strong-proof-of-conce…
https://vuldb.com/?ctiid.339082
https://vuldb.com/?id.339082
https://vuldb.com/?submit.718480