PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-10210

5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
chancms
Updated Sep 18, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

ChanCMS <= 3.3.0 - SQL Injection

yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \"key\" argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request. References: https://gitee.com/yanyutao0402/ChanCMS https://vuldb.com/?id.323483 https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e5.md https://nvd.nist.gov/vuln/detail/CVE-2025-10210 Remediation: Update to the latest version.

Used 3.1k times · url

CVE history: chancms

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →