PT-2025-34576 · Unknown · Yifang Cms

Yu Bao

·

Published

2025-08-24

·

Updated

2025-12-11

·

CVE-2025-9398

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: YiFang CMS versions up to 2.0.5
Description: A security issue has been identified in YiFang CMS. The exportInstallTable function within the app/utils/base/database/Migrate.php file is susceptible to information disclosure. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations: Versions prior to 2.0.5 should be updated. As a temporary workaround, consider restricting access to the app/utils/base/database/Migrate.php file.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-9398

Affected Products

Yifang Cms