Cross Site Scripting Vulnerability in YouDianCMS by YouDian Technology
CVE-2025-3531
Key Information:
- Vendor
- YouDian Technology
- Status
- Youdiancms
- Vendor
- CVE Published:
- 13 April 2025
Badges
Summary
A vulnerability has been identified in YouDianCMS version 9.5.21 that allows for cross site scripting (XSS) attacks. This issue resides within the file /App/Tpl/Admin/Default/Log/index.html, whereby manipulation of the UserName and LogType arguments can lead to the execution of malicious scripts in user browsers. Attackers can exploit this vulnerability remotely, posing significant security risks to users. The issue has been publicly disclosed, and the vendor has not yet provided a response to the concerns raised.
Affected Version(s)
YouDianCMS 9.5.21
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved