PT-2025-31000 · Yanyutao0402 · Chancms

Zast.Ai

·

Published

2025-07-27

·

Updated

2025-08-26

·

CVE-2025-8226

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yanyutao0402 ChanCMS versions through 3.1.2
Description A vulnerability exists in yanyutao0402 ChanCMS that may lead to information disclosure. The issue is related to the manipulation of the accessKey/secretKey arguments within an unknown function of the /sysApp/find file. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations Upgrade yanyutao0402 ChanCMS to version 3.1.3.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-8226

Affected Products

Chancms