PT-2025-31058 · Yanyutao0402 · Chancms
Zast.Ai
·
Published
2025-07-28
·
Updated
2025-07-28
·
CVE-2025-8266
Zast.Ai
·
Published
2025-07-28
·
Updated
2025-07-28
·
CVE-2025-8266
6.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
yanyutao0402 ChanCMS versions through 3.1.2
Description:
A critical vulnerability exists in yanyutao0402 ChanCMS. The `getArticle` function within the `app/modules/cms/controller/collect.js` file is susceptible to deserialization due to manipulation of the `targetUrl` argument. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations:
Upgrade to version 3.1.3 to address this issue.
Exploit
Fix
RCE
Deserialization of Untrusted Data