Home

Description

EN DE

A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

In westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab wurde eine Schwachstelle gefunden. Dies betrifft die Funktion Save der Datei src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java der Komponente Template Management Page. Durch Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.

PUBLISHED Reserved 2025-10-04 | Published 2025-10-05 | Updated 2025-10-06 | Assigner VulDB




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
LOW: 2.4CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
LOW: 2.4CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
3.3AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR

Problem types

Cross Site Scripting

Code Injection

Product status

2431154dac8d0735e04f1fd2a3c3556668fc8dab
affected

Timeline

2025-10-04:Advisory disclosed
2025-10-04:VulDB entry created
2025-10-04:VulDB entry last update

Credits

xmttz (VulDB User) reporter

References

vuldb.com/?id.327170 (VDB-327170 | westboy CicadasCMS Template Management TemplateFileServiceImpl.java save cross site scripting) vdb-entry technical-description

vuldb.com/?ctiid.327170 (VDB-327170 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.659789 (Submit #659789 | https://gitee.com/westboy/CicadasCMS/branches CicadasCMS v1.0 Cross Site Scripting) third-party-advisory

github.com/...tatingglamour/CVE/blob/main/CicadasCMS-XSS4.md exploit

cve.org (CVE-2025-11289)

nvd.nist.gov (CVE-2025-11289)

Download JSON