Record summary

CVE-2025-10211 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 31, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List3.3.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMChanCMS <= 3.3.0 - Server-Side Request ForgeryCVSS 6.3

yanyutao0402 ChanCMS 3.3.0 contains a server-side request forgery caused by manipulation of the "taskUrl" argument in /cms/collect/getArticle, letting remote attackers make arbitrary requests, exploit requires no special privileges.

Impact

Remote attackers can make arbitrary requests from the server, potentially accessing internal resources or sensitive data.

Remediation

Update to the latest version of ChanCMS.

WeaknessesCWE-918
AuthorsYu_Bao
Template tagscvecve2025chancmsssrfoastoobvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Shodan: http.html:"ChanCMS"
FOFA: body="ChanCMS"

Source: ProjectDiscovery

References

5
VDB-323484 | yanyutao0402 ChanCMS getArticle CollectController server-side request forgeryvdb entryTechnical description
https://vuldb.com/?id.323484