PT-2025-38694 · Muyucms · Muyucms

Eurekya

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-10787

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MuYuCMS versions prior to 2.7
Description A server-side request forgery condition exists in MuYuCMS. The issue is located in an unknown function within the /index/index.html file of the Add Fiend Link Handler component. Manipulation of the Link URL argument can trigger the issue, allowing for remote attacks. The exploit has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-10787

Affected Products

Muyucms