A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processing of the file publiccms-parent/publiccms/src/main/webapp/resource/plugins/pdfjs/viewer.html. The manipulation of the argument File leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named f1af17af004ca9345c6fe4d5936d87d008d26e75. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://github.com/sanluan/PublicCMS/commit/f1af17af004ca9345c6fe4d5936d87d008d26e75 | Patch |
https://github.com/sanluan/PublicCMS/issues/88 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.317099 | Permissions Required VDB Entry |
https://vuldb.com/?id.317099 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.619279 | Third Party Advisory VDB Entry |
Configurations
History
20 Aug 2025, 20:19
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:* | |
First Time |
Publiccms publiccms
Publiccms |
|
References | () https://github.com/sanluan/PublicCMS/commit/f1af17af004ca9345c6fe4d5936d87d008d26e75 - Patch | |
References | () https://github.com/sanluan/PublicCMS/issues/88 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.317099 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.317099 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.619279 - Third Party Advisory, VDB Entry |
22 Jul 2025, 13:05
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Jul 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-22 04:15
Updated : 2025-08-20 20:19
NVD link : CVE-2025-7953
Mitre link : CVE-2025-7953
CVE.ORG link : CVE-2025-7953
JSON object : View
Products Affected
publiccms
- publiccms
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')