A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md | Exploit |
| https://vuldb.com/?ctiid.298410 | Permissions Required |
| https://vuldb.com/?id.298410 | Permissions Required |
| https://vuldb.com/?submit.505754 | Third Party Advisory |
| https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md | Exploit |
Configurations
History
17 Jun 2026, 08:40
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) Se ha encontrado una vulnerabilidad en shishuocms 1.1. Se ha clasificado como problemática. Se ve afectada una función desconocida del archivo /manage/folder/add.json del componente Directory Deletion Page. La manipulación del argumento folderName provoca cross-site scripting. Es posible lanzar el ataque de forma remota. Se ha hecho público el exploit y puede que sea utilizado. |
05 Mar 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:qzw1210:shishuocms:1.1:*:*:*:*:*:*:* | |
| First Time |
Qzw1210 shishuocms
Qzw1210 |
|
| References | () https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md - Exploit | |
| References | () https://vuldb.com/?ctiid.298410 - Permissions Required | |
| References | () https://vuldb.com/?id.298410 - Permissions Required | |
| References | () https://vuldb.com/?submit.505754 - Third Party Advisory |
04 Mar 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md - |
04 Mar 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-03-04 01:15
Updated : 2026-06-17 08:40
NVD link : CVE-2025-1892
Mitre link : CVE-2025-1892
CVE.ORG link : CVE-2025-1892
JSON object : View
Products Affected
qzw1210
- shishuocms
