A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://gitee.com/wanglongcn/yifang/issues/IC41YQ | Exploit Issue Tracking |
https://gitee.com/wanglongcn/yifang/issues/IC41YQ | Exploit Issue Tracking |
https://vuldb.com/?ctiid.310676 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.310676 | Third Party Advisory VDB Entry |
Configurations
History
09 Jun 2025, 19:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wanglongcn
Wanglongcn yifang |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
CWE | CWE-79 | |
References | () https://gitee.com/wanglongcn/yifang/issues/IC41YQ - Exploit, Issue Tracking | |
References | () https://vuldb.com/?id.310676 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?ctiid.310676 - Permissions Required, Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:wanglongcn:yifang:*:*:*:*:*:*:*:* |
02 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
31 May 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-31 15:15
Updated : 2025-06-09 19:00
NVD link : CVE-2025-5383
Mitre link : CVE-2025-5383
JSON object : View
Products Affected
wanglongcn
- yifang
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')