MEDIUM
HuangDou UTCMS Config update.php server-side request forgery
Published Aug 25, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.36%
Description
A vulnerability was found in HuangDou UTCMS 9. This issue affects some unknown processing of the file app/modules/ut-frame/admin/update.php of the component Config Handler. Performing manipulation of the argument UPDATEURL results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 9StatusaffectedConstraints-
- Version
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25654 Advisory
- https://github.com/August829/Yu/blob/main/20250811_1.md relatedBroken Link
- https://github.com/August829/Yu/blob/main/20250811_1.md#poc exploitBroken Link
- https://vuldb.com/?ctiid.321238 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.321238 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.632537 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25654 | Advisory | |
| https://github.com/August829/Yu/blob/main/20250811_1.md | relatedBroken Link | |
| https://github.com/August829/Yu/blob/main/20250811_1.md#poc | exploitBroken Link | |
| https://vuldb.com/?ctiid.321238 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.321238 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.632537 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 25, 2025
Updated Aug 25, 2025
Reserved Aug 24, 2025
Link CVE-2025-9402
CISA Vulnrichment
Updated Aug 25, 2025
ENISA EUVD
EUVD-2025-25654 Assigner VulDB
Published Aug 25, 2025
Updated Aug 25, 2025
Exploited since n/a
Link EUVD-2025-25654