chshcms mccms Gf.php index server-side request forgery

CVE Details

Basic Information

Title chshcms mccms Gf.php index server-side request forgery
Type cve
Published 2025-05-29T20:31:04.905Z
Last Seen

Product Information

Vendor chshcms
Product mccms
Version 2.7

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A server-side request forgery vulnerability in chshcms mccms 2.7 allows remote attackers to manipulate the ‘pic’ argument in the Gf.php file’s index function. This could enable unauthorized actions on the server. The vendor has not responded to the disclosure.
AI Severity Medium
Vendor chshcms
Product mccms
Affected Version 2.7

Additional Information

CVE List
CWE List CWE-918
Bulletin Family
Source Data chshcms mccms 2.7

Source Information

Source Data chshcms mccms 2.7
Source Link

Description

A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Score Summary

Base Score: 5.3 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.