Server-Side Request Forgery in yanyutao0402 ChanCMS Affects Multiple Versions
CVE-2025-8133
Key Information:
- Vendor
Yanyutao0402
- Status
- Vendor
- CVE Published:
- 25 July 2025
Badges
What is CVE-2025-8133?
A server-side request forgery vulnerability exists in yanyutao0402 ChanCMS versions up to 3.1.2, specifically affecting the getArticle function in app/modules/api/service/gather.js. An unauthenticated attacker can manipulate the targetUrl argument to initiate requests to internal services, potentially leading to data exposure or further network exploitation. It is essential for users to upgrade to version 3.1.3 or later to mitigate this security risk.
Affected Version(s)
ChanCMS 3.1.0
ChanCMS 3.1.1
ChanCMS 3.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved