CVE-2025-69437: XSS
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69437?
CVE-2025-69437 is classified as a high severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-69437?
To fix CVE-2025-69437, upgrade PublicCMS to a version later than v5.202506.d to ensure the vulnerability is patched.
What is the impact of CVE-2025-69437?
The impact of CVE-2025-69437 includes the potential execution of malicious JavaScript when a user views an uploaded PDF, leading to unauthorized actions or data exposure.
Who is affected by CVE-2025-69437?
Users of PublicCMS versions v5.202506.d and earlier are affected by CVE-2025-69437 due to the stored XSS vulnerability.
Can CVE-2025-69437 be exploited remotely?
Yes, CVE-2025-69437 can be exploited remotely if an attacker uploads a malicious PDF which then targets users viewing the document.