Vulnerability Description
A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qzw1210 | Shishuocms | 1.1 |
Related Weaknesses (CWE)
References
- https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8Exploit
- https://vuldb.com/?ctiid.298410Permissions Required
- https://vuldb.com/?id.298410Permissions Required
- https://vuldb.com/?submit.505754Third Party Advisory
- https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8Exploit
FAQ
What is CVE-2025-1892?
CVE-2025-1892 is a vulnerability with a CVSS score of 2.4 (LOW). A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The ma...
How severe is CVE-2025-1892?
CVE-2025-1892 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1892?
Check the references section above for vendor advisories and patch information. Affected products include: Qzw1210 Shishuocms.