Junglewise Threat Intelligence

CVE-2025-52335: EyouCMS XSS in index.php

CVE-2025-52335 · Severity: medium · CVSS 6.1 · Published 2025-08-14

Technologies: EyouCMS. Vendors: EyouCMS.

Executive brief

EyouCMS, a content management system used for building websites, contains a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a malicious link, an attacker could steal sensitive information like session cookies or perform actions on behalf of the user. This could lead to unauthorized access to the website's management interface or the exposure of private user data.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in EyouCMS version 1.7.3 within the index.php component. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a specially crafted URL to a victim. If the victim visits the link, the attacker's malicious JavaScript executes within the context of the victim's browser session, potentially allowing for the theft of session tokens or other sensitive information. The attack requires user interaction and has a CVSS base score of 6.1.

Affected products

  • EyouCMS EyouCMS 1.7.3

Timeline

  • 2025-08-14: advisory: Initial disclosure of CVE-2025-52335

References

Related threats