PT-2025-53662 · Sohu · Sohutv Cachecloud

Zast.Ai

·

Published

2025-12-28

·

Updated

2026-01-07

·

CVE-2025-15146

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SohuTV CacheCloud versions up to 3.2.0
Description A security issue exists in SohuTV CacheCloud. Manipulation of the doUserList function within the file src/main/java/com/sohu/cache/web/controller/UserManageController.java can lead to cross site scripting. This attack can be initiated remotely. The exploit is publicly available. The project was notified of the issue but has not yet responded.
Recommendations Versions prior to 3.2.0 should be updated. As a temporary workaround, consider restricting access to the doUserList function until a patch is available.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15146

Affected Products

Sohutv Cachecloud