CVE 4.8 MEDIUM

westboy CicadasCMS Template Management TemplateFileServiceImpl.java save cross site scripting_CVE-2025-11289

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Basic Information

ID CVE-2025-11289
Source VulDB
Published Oct 5, 2025 at 10:32

Affected Product

Vendor westboy
Product CicadasCMS
Version 2431154dac8d0735e04f1fd2a3c3556668fc8dab
Affected Versions westboy CicadasCMS 2431154dac8d0735e04f1fd2a3c3556668fc8dab

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.