A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/stevenchen0x01/CVE2/blob/main/cve2.md | Broken Link Exploit Third Party Advisory |
https://vuldb.com/?ctiid.295080 | Permissions Required |
https://vuldb.com/?id.295080 | Third Party Advisory |
https://vuldb.com/?submit.495366 | Third Party Advisory |
Configurations
History
20 Feb 2025, 15:58
Type | Values Removed | Values Added |
---|---|---|
First Time |
Xunruicms
Xunruicms xunruicms |
|
CPE | cpe:2.3:a:xunruicms:xunruicms:4.6.3:*:*:*:*:*:*:* | |
Summary |
|
|
References | () https://github.com/stevenchen0x01/CVE2/blob/main/cve2.md - Broken Link, Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.295080 - Permissions Required | |
References | () https://vuldb.com/?id.295080 - Third Party Advisory | |
References | () https://vuldb.com/?submit.495366 - Third Party Advisory |
11 Feb 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 06:15
Updated : 2025-02-20 15:58
NVD link : CVE-2025-1177
Mitre link : CVE-2025-1177
CVE.ORG link : CVE-2025-1177
JSON object : View
Products Affected
xunruicms
- xunruicms