MEDIUM
YiFang CMS Migrate.php exportInstallTable information disclosure
Published Aug 24, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.49%
Description
A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file app/utils/base/database/Migrate.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- ≤ 2.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25652 Advisory
- https://github.com/August829/Yu/blob/main/20250811_5.md relatedBroken Link
- https://github.com/August829/Yu/blob/main/20250811_5.md#poc exploitBroken Link
- https://vuldb.com/?ctiid.321234 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.321234 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.632533 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25652 | Advisory | |
| https://github.com/August829/Yu/blob/main/20250811_5.md | relatedBroken Link | |
| https://github.com/August829/Yu/blob/main/20250811_5.md#poc | exploitBroken Link | |
| https://vuldb.com/?ctiid.321234 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.321234 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.632533 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 24, 2025
Updated Aug 25, 2025
Reserved Aug 24, 2025
Link CVE-2025-9398
CISA Vulnrichment
Updated Aug 25, 2025
Red Hat
No data
GitHub
No data