Executive brief
EyouCMS, a content management system used for building websites, contains a security flaw that allows attackers to inject malicious scripts into the administrative login page. If an administrative user clicks a specially crafted link, the attacker could potentially hijack their session, steal sensitive information, or perform unauthorized actions on the website. This could lead to a full compromise of the site's management interface.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in EyouCMS version 1.6.7. The flaw is located in the administrative interface accessible via /login.php?m=admin&c=System&a=web&lang=cn, where user-supplied input is improperly neutralized before being rendered in the web page. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into visiting a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session token theft or unauthorized administrative actions. A proof-of-concept has been reported in public repositories.
Affected products
- EyouCMS EyouCMS 1.6.7
Timeline
- 2025-08-07: advisory: NVD published the CVE record.
- 2025-08-07: other: CISA-ADP provided CVSS enrichment.