CVE-2025-15094

MEDIUM

FlyCMS < 2019-12-20 - Cross-Site Scripting via User Login Redirect URL

Title source: llm
STIX 2.1

Description

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.338423
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.338423
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.708997
Exploit, Issue Tracking, Vendor Advisory exploit issue-tracking
https://github.com/sunkaifei/FlyCms/issues/16
Various Sources product
https://github.com/sunkaifei/FlyCms/

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
sunkaifei/flycms < 2019-12-20
Published Dec 26, 2025
Tracked Since Feb 18, 2026