CVE-2025-45529: High severity sscms vulnerability
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45529?
CVE-2025-45529 has a moderate severity rating due to its potential to expose sensitive files.
How do I fix CVE-2025-45529?
To fix CVE-2025-45529, update SSCMS to version 7.3.2 or later, which includes a patch for this vulnerability.
What are the consequences of exploiting CVE-2025-45529?
Exploiting CVE-2025-45529 can allow an attacker to access arbitrary files on the server, potentially leading to data leaks or service disruption.
Which versions of SSCMS are affected by CVE-2025-45529?
SSCMS versions prior to 7.3.2 are affected by CVE-2025-45529.
How can the exploitation of CVE-2025-45529 be detected?
Exploitation attempts for CVE-2025-45529 can be detected by monitoring application logs for unusual GET requests targeting /cms/templates/templatesAssetsEditor.