Server-Side Request Forgery Vulnerability in ChanCMS by yanyutao0402
CVE-2025-10211
Key Information:
- Vendor
Yanyutao0402
- Status
- Vendor
- CVE Published:
- 10 September 2025
Badges
What is CVE-2025-10211?
A security vulnerability in ChanCMS version 3.3.0 allows an attacker to manipulate the taskUrl
argument within the CollectController
function located in the /cms/collect/getArticle
file. This manipulation can result in server-side request forgery, enabling the attacker to initiate unauthorized requests to internal resources. The exploit is publicly disclosed and can potentially be executed remotely, increasing the risk to affected systems. Early attempts to inform the vendor about this vulnerability have gone unanswered, highlighting an urgent need for users to apply mitigations.
Affected Version(s)
ChanCMS 3.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved