SQL Injection Vulnerability in yanyutao0402 ChanCMS Product
CVE-2025-10106
Key Information:
- Vendor
Yanyutao0402
- Status
- Vendor
- CVE Published:
- 8 September 2025
Badges
What is CVE-2025-10106?
A SQL injection vulnerability exists in yanyutao0402 ChanCMS versions up to 3.3.1, specifically within the /cms/collect/search file. Attackers can exploit this weakness by manipulating the 'keyword' argument, enabling them to conduct unauthorized SQL operations. This vulnerability can be leveraged remotely, posing significant risks to the integrity of the database and overall system security. Prompt remediation and patching are essential to safeguard against potential exploitation.
Affected Version(s)
ChanCMS 3.3.0
ChanCMS 3.3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved