PT-2025-53432 · Flycms · Flycms

Zast.Ai

·

Published

2025-12-26

·

Updated

2025-12-26

·

CVE-2025-15094

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FlyCMS (affected versions not specified)
Description A flaw exists in the User Login functionality of FlyCMS. Specifically, manipulation of the redirectUrl argument within the userLogin function in the file src/main/java/com/flycms/web/front/UserController.java can lead to cross-site scripting. This issue is remotely exploitable, and details about its exploitation are publicly available. The project maintainers were notified but have not yet responded.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15094

Affected Products

Flycms