CVE-2025-64048

Source
https://cve.org/CVERecord?id=CVE-2025-64048
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64048.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64048
Published
2025-11-24T20:15:50.683Z
Modified
2026-03-13T03:38:19.370388Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64048.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.4"
            }
        ]
    }
]