CVE-2025-5383

5/31/2025 3:15:20 PM
2 روز قبل
2 روز قبل
1
Reporter :cna@vuldb.com
Modified :5/31/2025 3:15:20 PM
Problem Data :CWE-79

Description

A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Cvss Version 2.0

3.3 AV:N/AC:L/Au:M/C:N/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication Multiple
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

Cvss Version 3.1

2.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None

Cvss Version 4.0

4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction
Vulnerability Complexity None
Vulnerability Impact Low

EPSS

Epss Score 0.00026
Epss Percentile 0.05711

ریسک پائین:: این آسیب پذیری احتمال ارائه Exploit پائینی دارد. به روز رسانی و نظارت معمولی را لحاظ نمائید.

پیشنهادات:
  • به بروزرسانی مداوم سیستم و یا شبکه خود ادامه دهید.
  • از بروزرسانی های آتی این آسیب پذیری مطلع شوید.