Description
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
In yanyutao0402 ChanCMS up to 3.3.2 wurde eine Schwachstelle gefunden. Es betrifft die Funktion hasUse der Datei /cms/model/hasUse. Die Veränderung des Parameters ID resultiert in sql injection. Der Angriff kann remote ausgeführt werden. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.
Problem types
Product status
3.3.1
3.3.2
Timeline
2025-10-17: | Advisory disclosed |
2025-10-17: | VulDB entry created |
2025-10-17: | VulDB entry last update |
Credits
Narcher (VulDB User)
References
vuldb.com/?id.328914 (VDB-328914 | yanyutao0402 ChanCMS hasUse sql injection)
vuldb.com/?ctiid.328914 (VDB-328914 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.670274 (Submit #670274 | yanyutao0402 ChanCMS <=3.3.2 SQL Injection)
github.com/.../main/Vulnerability_Discovery/ChanCMSv3.3.2.md
github.com/.../main/Vulnerability_Discovery/ChanCMSv3.3.2.md