CVE-2025-10210
yanyutao0402 ChanCMS Api.js search sql injection
Record summary
CVE-2025-10210 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 3.0 | affected | |
| 3.1 | affected | ||
| 3.2 | affected | ||
| 3.3.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMChanCMS <= 3.3.0 - SQL InjectionCVSS 6.3
yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \"key\" argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.
Impact
Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or database compromise.
Remediation
Update to the latest version.
Source: ProjectDiscovery