Security Advisory

CVE-2025-15374

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-31 04:32:08
Last updated 2026-02-24 06:19:48
Assigner VulDB
State PUBLISHED

Description

A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing a manipulation of the argument content results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor is "[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8".