PT-2025-30729 · Chancms · Chancms
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ChanCMS versions up to 3.1.2
Description
A critical issue exists in ChanCMS that allows for server-side request forgery. The
getArticle function within the app/modules/api/service/gather.js file is susceptible to manipulation via the targetUrl argument. This allows for remote exploitation.Recommendations
Upgrade ChanCMS to version 3.1.3.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chancms