CVE-2025-15143

A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/FilemanagerLogic.php of the component Backend Template Management. The manipulation of the argument content results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://note-hxlab.wetolink.com/share/XfINjg5i25Ud Exploit Third Party Advisory
https://vuldb.com/?ctiid.338521 Permissions Required VDB Entry
https://vuldb.com/?id.338521 Third Party Advisory VDB Entry
https://vuldb.com/?submit.716078 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-28 16:15

Updated : 2025-12-30 20:31


NVD link : CVE-2025-15143

Mitre link : CVE-2025-15143

CVE.ORG link : CVE-2025-15143


JSON object : View

Products Affected

eyoucms

  • eyoucms
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')