Metrics
Affected Vendors & Products
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 31 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eyoucms
Eyoucms eyoucms |
|
| CPEs | cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eyoucms
Eyoucms eyoucms |
Wed, 31 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing manipulation of the argument content results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor is "[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8". | |
| Title | EyouCMS Ask Module Ask.php cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-31T04:32:08.144Z
Updated: 2026-01-02T14:37:32.085Z
Reserved: 2025-12-30T18:46:08.945Z
Link: CVE-2025-15374
Updated: 2026-01-02T14:21:23.816Z
Status : Modified
Published: 2025-12-31T05:16:03.670
Modified: 2026-01-02T15:15:58.870
Link: CVE-2025-15374
No data.