PT-2025-40889 · Cmseasy · Cmseasy
Tiancesec
+1
·
Published
2025-10-06
·
Updated
2025-12-12
·
CVE-2025-11332
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CmsEasy versions up to 7.7.7
Description
A flaw exists in CmsEasy that may allow for cross site scripting. This issue affects an unknown function within the
lib/inc/view.php component of the URL Handler. Manipulation of the PHP SELF argument can be used to exploit this issue, and the attack can be launched remotely. The details of the issue have been publicly disclosed.Recommendations
Update CmsEasy to a version newer than 7.7.7.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cmseasy