Vulnerability Description
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mrcms | Mrcms | 3.1.2 |
Related Weaknesses (CWE)
References
- https://flowus.cn/share/8838861d-0b32-4314-a13d-edb22b72cebcExploitThird Party Advisory
FAQ
What is CVE-2025-25768?
CVE-2025-25768 is a vulnerability with a CVSS score of 5.4 (MEDIUM). MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary ...
How severe is CVE-2025-25768?
CVE-2025-25768 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25768?
Check the references section above for vendor advisories and patch information. Affected products include: Mrcms Mrcms.