PT-2025-53660 · Dayrui · Xunruicms
Vuldb
+1
·
Published
2025-12-28
·
Updated
2026-01-07
·
CVE-2025-15144
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
dayrui XunRuiCMS versions up to 4.7.1
Description
A flaw exists in dayrui XunRuiCMS that allows for cross site scripting. The issue is located in the JSONP Callback Handler component, specifically within the
dr show error/dr exit msg function of the /dayrui/Fcms/Init.php file. Manipulation of the callback argument can trigger the flaw. The exploit is publicly available. The vendor was contacted but did not respond.Recommendations
Versions prior to 4.7.1 should be updated.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xunruicms