PT-2025-30729 · Chancms · Chancms

·

CVE-2025-8133

·

Published

2025-07-25

·

Updated

2025-07-25

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ChanCMS versions up to 3.1.2
Description A critical issue exists in ChanCMS that allows for server-side request forgery. The getArticle function within the app/modules/api/service/gather.js file is susceptible to manipulation via the targetUrl argument. This allows for remote exploitation.
Recommendations Upgrade ChanCMS to version 3.1.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8133

Affected Products

Chancms