Executive brief
EyouCMS, an open-source content management system used for building corporate websites, contains a security flaw in its API component. An attacker can exploit this vulnerability to run unauthorized database commands, potentially leading to the exposure of sensitive information or modification of website data. This issue specifically affects the way the system handles 'likes' or interactions on certain pages.
Technical details
A SQL injection vulnerability exists in EyouCMS versions up to and including 1.7.1. The flaw is located in the API component within the /index.php file (specifically the get_ask_details method). The root cause is improper neutralization of the 'click_like' parameter, which allows an attacker to inject malicious SQL statements such as 'extractvalue' payloads. While the attack can be executed remotely, the CVSS vector suggests high privileges (PR:H) may be required. A public exploit has been disclosed, but as of the advisory date, the vendor has not released a formal patch.
Affected products
- weng-xianhu EyouCMS up to 1.7.1
Timeline
- 2026-05-31: disclosed: Issue reported on GitHub repository
- 2026-06-29: advisory: CVE published and NVD record created