CVE-2025-15375

A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be launched remotely. The exploit has been published and may be used. The vendor is "[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8".
Configurations

Configuration 1 (hide)

cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-31 05:16

Updated : 2026-02-24 07:17


NVD link : CVE-2025-15375

Mitre link : CVE-2025-15375

CVE.ORG link : CVE-2025-15375


JSON object : View

Products Affected

eyoucms

  • eyoucms
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data