Information Disclosure Vulnerability in YiFang CMS by YiFang
CVE-2025-9398
Key Information:
Badges
What is CVE-2025-9398?
A security vulnerability exists in YiFang CMS versions up to 2.0.5, specifically within the exportInstallTable function located in app/utils/base/database/Migrate.php. This vulnerability allows remote attackers to manipulate database exports, leading to unauthorized information disclosure. The issue has been publicly disclosed, and despite early notification to the vendor, no response has been received. It is imperative for users of affected versions to review their security measures and implement mitigations to safeguard their data.
Affected Version(s)
CMS 2.0.0
CMS 2.0.1
CMS 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
