A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
References
| Link | Resource |
|---|---|
| https://gitee.com/chancms/ChanCMS | Product |
| https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689 | Permissions Required |
| https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689?source=copy_link | Permissions Required |
Configurations
History
18 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1336 |
17 Dec 2025, 19:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:chancms:chancms:3.3.4:*:*:*:*:*:*:* | |
| CWE | CWE-94 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Chancms chancms
Chancms |
|
| References | () https://gitee.com/chancms/ChanCMS - Product | |
| References | () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689 - Permissions Required | |
| References | () https://www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689?source=copy_link - Permissions Required |
10 Dec 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-10 20:16
Updated : 2025-12-18 21:15
NVD link : CVE-2025-65602
Mitre link : CVE-2025-65602
CVE.ORG link : CVE-2025-65602
JSON object : View
Products Affected
chancms
- chancms
