PT-2025-31002 · Chancms · Chancms

Zast.Ai

·

Published

2025-07-27

·

Updated

2025-08-26

·

CVE-2025-8228

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChanCMS versions up to 3.1.2
Description A critical server-side request forgery (SSRF) vulnerability exists in the getPages function of the /cms/collect/getPages file. Manipulation of the targetUrl argument can lead to unauthorized access to internal server resources. The exploit has been publicly disclosed.
Recommendations Upgrade to version 3.1.3.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-8228

Affected Products

Chancms