PT-2025-49023 · Xunruicms · Xunruicms

Nobb

·

Published

2025-12-04

·

Updated

2026-02-24

·

CVE-2025-14005

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dayrui XunRuiCMS versions up to 4.7.1
Description A cross site scripting issue exists in dayrui XunRuiCMS. The issue is related to an unknown functionality within the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 of the Add Display Name Field component. Manipulation of the data[name] argument can lead to the execution of cross site scripting attacks remotely. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 4.7.1 should be updated.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-14005

Affected Products

Xunruicms