Sanluan PublicCMS preview.html redirect

CVE Details

Basic Information

Title Sanluan PublicCMS preview.html redirect
Type cve
Published 2025-07-22T01:32:06.463Z
Modified 2025-07-22T01:32:06.463Z

Product Information

Vendor Sanluan
Product PublicCMS
Version 5.202506.a

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description This vulnerability is an open redirect issue in Sanluan PublicCMS version 5.202506.a. It allows remote attackers to redirect users to malicious websites by manipulating the ‘url’ argument in the preview.html file. A patch is available to fix this issue.
AI Severity Medium
AI Vendor Sanluan
AI Product PublicCMS
AI Version 5.202506.a

Affected Products

  • Sanluan PublicCMS 5.202506.a

Additional Information

CWE List CWE-601
Source VulDB

Description

A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file publiccms-parent/publiccms/src/main/resources/templates/admin/cmsDiy/preview.html. The manipulation of the argument url leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named c1e79f124e3f4c458315d908ed7dee06f9f12a76/f1af17af004ca9345c6fe4d5936d87d008d26e75. It is recommended to apply a patch to fix this issue.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.