Record summary

CVE-2025-10210 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.0affected
3.1affected
3.2affected
3.3.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMChanCMS <= 3.3.0 - SQL InjectionCVSS 6.3

yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \"key\" argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.

Impact

Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or database compromise.

Remediation

Update to the latest version.

WeaknessesCWE-89
AuthorsYu_Bao
Template tagscvecve2025chancmssqli
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Shodan: http.html:"ChanCMS"
FOFA: body="ChanCMS"

Source: ProjectDiscovery

References

5