CVE-2025-1177
MEDIUMXunruicms - Insecure Deserialization
Title source: ruleDescription
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
6.3
EPSS
0.0016
EPSS Percentile
36.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
CWE-20
Status
published
Affected Products (1)
xunruicms/xunruicms
Timeline
Published
Feb 11, 2025
Tracked Since
Feb 18, 2026