A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/groovy/exec of the component API Endpoint. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/byxs0x0/cve/issues/7 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.311002 | Permissions Required VDB Entry |
https://vuldb.com/?id.311002 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.587199 | Third Party Advisory VDB Entry Exploit |
Configurations
History
03 Oct 2025, 01:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
1000mz chestnutcms
1000mz |
|
CPE | cpe:2.3:a:1000mz:chestnutcms:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
References | () https://github.com/byxs0x0/cve/issues/7 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.311002 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.311002 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.587199 - Third Party Advisory, VDB Entry, Exploit |
04 Jun 2025, 14:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
04 Jun 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-04 03:15
Updated : 2025-10-03 01:04
NVD link : CVE-2025-5552
Mitre link : CVE-2025-5552
CVE.ORG link : CVE-2025-5552
JSON object : View
Products Affected
1000mz
- chestnutcms
CWE