PT-2025-53660 · Dayrui · Xunruicms

Vuldb

+1

·

Published

2025-12-28

·

Updated

2026-01-07

·

CVE-2025-15144

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dayrui XunRuiCMS versions up to 4.7.1
Description A flaw exists in dayrui XunRuiCMS that allows for cross site scripting. The issue is located in the JSONP Callback Handler component, specifically within the dr show error/dr exit msg function of the /dayrui/Fcms/Init.php file. Manipulation of the callback argument can trigger the flaw. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations Versions prior to 4.7.1 should be updated.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15144

Affected Products

Xunruicms