ChanCMS <= 3.3.0 - SQL Injection
yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \"key\" argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request. References: https://gitee.com/yanyutao0402/ChanCMS https://vuldb.com/?id.323483 https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e5.md https://nvd.nist.gov/vuln/detail/CVE-2025-10210 Remediation: Update to the latest version.
Used 3.1k times · url