PT-2025-49030 · Dayrui · Xunruicms

Nobb

·

Published

2025-12-04

·

Updated

2025-12-05

·

CVE-2025-14008

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dayrui XunRuiCMS versions up to 4.7.1
Description A server-side request forgery condition exists in dayrui XunRuiCMS. The issue is located in the file admin79f2ec220c7e.php?c=api&m=test site domain within the Project Domain Change Test component. Manipulation of the v parameter can trigger the flaw, allowing for remote exploitation. The exploit has been published. The vendor was contacted but did not respond.
Recommendations Versions prior to 4.7.1 should be used.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-14008

Affected Products

Xunruicms