CVE-2025-14008

Source
https://cve.org/CVERecord?id=CVE-2025-14008
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14008.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14008
Published
2025-12-04T15:15:56.057Z
Modified
2026-03-14T12:41:33.326771Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=testsitedomain of the component Project Domain Change Test. This manipulation of the argument v causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.7.1"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14008.json"