CVE-2025-15204

Source
https://cve.org/CVERecord?id=CVE-2025-15204
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15204.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15204
Published
2025-12-29T21:15:43.157Z
Modified
2026-03-15T22:20:41.480259Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Git / github.com/sohutv/cachecloud

Affected ranges

Type
GIT
Repo
https://github.com/sohutv/cachecloud
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.2"
        }
    ]
}

Affected versions

1.*
1.0
1.1
1.2
2.*
2.0
2.1
2.2
3.*
3.0
3.1
3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15204.json"