PT-2025-54272 · Eyoucms · Eyoucms

Pemic

·

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2025-15374

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EyouCMS versions prior to 1.7.8
Description A cross site scripting issue exists in EyouCMS. The issue is related to the manipulation of the content argument within an unknown function of the file application/home/model/Ask.php, part of the Ask Module. This can be exploited remotely. The exploit is publicly available.
Recommendations Update to version 1.7.8 or later.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15374

Affected Products

Eyoucms