CVE-2025-10211
yanyutao0402 ChanCMS getArticle CollectController server-side request forgery
Record summary
CVE-2025-10211 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the argument taskUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 31, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
chancmsBrowse chancms / chancms | VulnCheck | Version data not supplied | |
| CVE List | 3.3.0 | affected | |
Nuclei templates
1ProjectDiscoveryMEDIUMChanCMS <= 3.3.0 - Server-Side Request ForgeryCVSS 6.3
yanyutao0402 ChanCMS 3.3.0 contains a server-side request forgery caused by manipulation of the "taskUrl" argument in /cms/collect/getArticle, letting remote attackers make arbitrary requests, exploit requires no special privileges.
Impact
Remote attackers can make arbitrary requests from the server, potentially accessing internal resources or sensitive data.
Remediation
Update to the latest version of ChanCMS.
Source: ProjectDiscovery