CVE-2025-65602

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chancms:chancms:3.3.4:*:*:*:*:*:*:*

History

18 Dec 2025, 21:15

Type Values Removed Values Added
CWE CWE-1336

17 Dec 2025, 19:31

Type Values Removed Values Added
CPE cpe:2.3:a:chancms:chancms:3.3.4:*:*:*:*:*:*:*
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Chancms chancms
Chancms
References () https://gitee.com/chancms/ChanCMS - () https://gitee.com/chancms/ChanCMS - Product
References () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689 - () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689 - Permissions Required
References () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689?source=copy_link - () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689?source=copy_link - Permissions Required

10 Dec 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 20:16

Updated : 2025-12-18 21:15


NVD link : CVE-2025-65602

Mitre link : CVE-2025-65602

CVE.ORG link : CVE-2025-65602


JSON object : View

Products Affected

chancms

  • chancms
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine