PT-2025-40889 · Cmseasy · Cmseasy

Tiancesec

+1

·

Published

2025-10-06

·

Updated

2025-12-12

·

CVE-2025-11332

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CmsEasy versions up to 7.7.7
Description A flaw exists in CmsEasy that may allow for cross site scripting. This issue affects an unknown function within the lib/inc/view.php component of the URL Handler. Manipulation of the PHP SELF argument can be used to exploit this issue, and the attack can be launched remotely. The details of the issue have been publicly disclosed.
Recommendations Update CmsEasy to a version newer than 7.7.7.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11332

Affected Products

Cmseasy