PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-10211

5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
chancms
Updated Sep 18, 2026View on NVD →
S4E scanner

ChanCMS <= 3.3.0 - Server-Side Request Forgery

yanyutao0402 ChanCMS 3.3.0 contains a server-side request forgery caused by manipulation of the "taskUrl" argument in /cms/collect/getArticle, letting remote attackers make arbitrary requests, exploit requires no special privileges. References: https://gitee.com/yanyutao0402/ChanCMS https://vuldb.com/?id.323484 Remediation: Update to the latest version of ChanCMS.

Used 3.2k times · url

CVE history: chancms

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →