SQL Injection Vulnerability in ChanCMS by yanyutao0402
CVE-2025-10210
Key Information:
- Vendor
Yanyutao0402
- Status
- Vendor
- CVE Published:
- 10 September 2025
Badges
What is CVE-2025-10210?
A security flaw has been discovered in ChanCMS by yanyutao0402, specifically within the Search function found in app/modules/api/service/Api.js. This vulnerability arises from improper handling of user input, which may lead to SQL injection attacks. Attackers can manipulate the 'key' argument remotely to execute unauthorized SQL queries. The potential for exploitation is augmented by the fact that details of this flaw have been made publicly available, and the vendor has not yet responded to disclosures regarding this issue.
Affected Version(s)
ChanCMS 3.0
ChanCMS 3.1
ChanCMS 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved