PT-2025-34577 · Unknown · Yifang Cms
Yu Bao
·
Published
2025-08-25
·
Updated
2025-12-11
·
CVE-2025-9399
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YiFang CMS versions up to 2.0.5
Description
A flaw exists in YiFang CMS up to version 2.0.5, specifically within an unknown functionality of the
app/logic/L tool.php file. Manipulating the new url argument can lead to a SQL injection. This issue can be exploited remotely. The exploit is publicly available and may be used. The vendor was contacted regarding this disclosure but did not respond.Recommendations
Versions prior to 2.0.5 should be updated.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yifang Cms