A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown code of the file /index.php/sysmanage/Login. Such manipulation of the argument Name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared 07fly
07fly 07fly-cms
07fly 07flycms
07fly 07flycrm
Vendors & Products 07fly
07fly 07fly-cms
07fly 07flycms
07fly 07flycrm

Fri, 19 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown code of the file /index.php/sysmanage/Login. Such manipulation of the argument Name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way.
Title 07FLYCMS/07FLY-CMS/07FlyCRM Login cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-19T12:32:11.985Z

Updated: 2025-09-19T13:03:55.881Z

Reserved: 2025-09-19T06:07:26.582Z

Link: CVE-2025-10711

cve-icon Vulnrichment

Updated: 2025-09-19T13:03:44.079Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-19T13:15:43.470

Modified: 2025-09-19T16:00:27.847

Link: CVE-2025-10711

cve-icon Redhat

No data.