Home

Description

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-10 | Updated 2025-12-10 | Assigner mitre

References

gitee.com/chancms/ChanCMS

www.notion.so/...235ba380fc9973e16c06258689?source=copy_link

www.notion.so/...icated-RCE-2a3ee9235ba380fc9973e16c06258689

cve.org (CVE-2025-65602)

nvd.nist.gov (CVE-2025-65602)

Download JSON