PT-2025-53690 · Sohu · Sohutv Cachecloud
Zast.Ai
·
Published
2025-12-29
·
Updated
2026-01-07
·
CVE-2025-15172
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SohuTV CacheCloud versions up to 3.2.0
Description
A security flaw exists in SohuTV CacheCloud that allows for cross site scripting. This issue impacts the
preview function within the file src/main/java/com/sohu/cache/web/controller/RedisConfigTemplateController.java. The attack can be executed remotely. The exploit has been released publicly and may be exploited. The project was informed of the issue but has not yet responded.Recommendations
Versions up to 3.2.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sohutv Cachecloud