Open Redirect Vulnerability in Sanluan PublicCMS from Sanluan
CVE-2025-7949
Key Information:
Badges
What is CVE-2025-7949?
A vulnerability in Sanluan PublicCMS allows an attacker to exploit an unknown functionality in the template file preview.html. By manipulating the 'url' argument, an open redirect can be triggered, potentially leading to unauthorized access or phishing attacks. The vulnerability affects all versions of PublicCMS up to 5.202506.a and can be exploited remotely. A patch has been released to address this issue, and it is strongly recommended to apply it to safeguard against potential exploits.
Affected Version(s)
PublicCMS 5.202506.a
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved