CVE-2025-15144: dayrui XunRuiCMS JSONP Callback Init.php dr_exit_msg cross site scripting
A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. The impacted element is the function drshowerror/drexitmsg of the file /dayrui/Fcms/Init.php of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15144?
CVE-2025-15144 is classified as a security vulnerability that allows cross-site scripting due to a flaw in the JSONP Callback Handler.
How do I fix CVE-2025-15144?
To fix CVE-2025-15144, update XunRuiCMS to the latest version, which addresses the vulnerabilities associated with this issue.
What versions of XunRuiCMS are affected by CVE-2025-15144?
CVE-2025-15144 affects all versions of XunRuiCMS up to and including version 4.7.1.
What type of attack is associated with CVE-2025-15144?
CVE-2025-15144 is associated with cross-site scripting attacks that exploit the JSONP Callback Handler.
How can I tell if my website is vulnerable to CVE-2025-15144?
You can determine if your website is vulnerable to CVE-2025-15144 by checking if it uses an affected version of XunRuiCMS and reviewing its error handling functions.