CVE-2025-14005: dayrui XunRuiCMS Add Display Name Field admind45f74adbd95.php cross site scripting
A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 of the component Add Display Name Field. Executing a manipulation of the argument data[name] can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14005?
The severity of CVE-2025-14005 is currently classified as high due to its potential impact on the confidentiality and integrity of the application.
How do I fix CVE-2025-14005?
To fix CVE-2025-14005, update your XunRuiCMS to version 4.7.2 or later, where the vulnerability has been addressed.
What are the potential consequences of CVE-2025-14005?
The consequences of CVE-2025-14005 can include unauthorized access to sensitive data and possible manipulation of the application's functionality.
Which versions of XunRuiCMS are affected by CVE-2025-14005?
CVE-2025-14005 affects XunRuiCMS versions up to and including 4.7.1.
Is CVE-2025-14005 being actively exploited?
As of the latest information, there are no confirmed reports of active exploitation for CVE-2025-14005, but it is recommended to apply the patch promptly.