PT-2025-34577 · Unknown · Yifang Cms

Yu Bao

·

Published

2025-08-25

·

Updated

2025-12-11

·

CVE-2025-9399

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YiFang CMS versions up to 2.0.5
Description A flaw exists in YiFang CMS up to version 2.0.5, specifically within an unknown functionality of the app/logic/L tool.php file. Manipulating the new url argument can lead to a SQL injection. This issue can be exploited remotely. The exploit is publicly available and may be used. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions prior to 2.0.5 should be updated.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9399

Affected Products

Yifang Cms