Description
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
In yanyutao0402 ChanCMS up to 3.3.2 ist eine Schwachstelle entdeckt worden. Das betrifft die Funktion getArticle der Datei app\modules\cms\controller\gather.js. Die Bearbeitung verursacht code injection. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
3.3.1
3.3.2
Timeline
2025-10-17: | Advisory disclosed |
2025-10-17: | VulDB entry created |
2025-10-17: | VulDB entry last update |
Credits
Narcher (VulDB User)
References
vuldb.com/?id.328915 (VDB-328915 | yanyutao0402 ChanCMS gather.js getArticle code injection)
vuldb.com/?ctiid.328915 (VDB-328915 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.671338 (Submit #671338 | yanyutao0402 ChanCMS <=v3.3.2 Code Injection)
github.com/.../main/Vulnerability_Discovery/ChanCMSv3.3.2.md
github.com/.../main/Vulnerability_Discovery/ChanCMSv3.3.2.md