CVE-2025-52159

Hardcoded credentials in default configuration of PPress 0.0.9.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yandaozi:ppress:0.0.9:beta:*:*:*:*:*:*

History

25 Sep 2025, 19:34

Type Values Removed Values Added
References () https://github.com/quarter77/PPress-CMS-session-forgery-SSTI-vulnerability-leads-to-remote-command-execution - () https://github.com/quarter77/PPress-CMS-session-forgery-SSTI-vulnerability-leads-to-remote-command-execution - Third Party Advisory
References () https://github.com/quarter77/PPress-CMS_vulnerability_chain_details/blob/main/CVE-2025-52159%20Details.md - () https://github.com/quarter77/PPress-CMS_vulnerability_chain_details/blob/main/CVE-2025-52159%20Details.md - Exploit, Third Party Advisory
First Time Yandaozi ppress
Yandaozi
CPE cpe:2.3:a:yandaozi:ppress:0.0.9:beta:*:*:*:*:*:*

19 Sep 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-798

19 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-19 20:15

Updated : 2025-09-25 19:34


NVD link : CVE-2025-52159

Mitre link : CVE-2025-52159

CVE.ORG link : CVE-2025-52159


JSON object : View

Products Affected

yandaozi

  • ppress
CWE
CWE-798

Use of Hard-coded Credentials