CVE-2025-7949: Sanluan PublicCMS preview.html redirect
A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file publiccms-parent/publiccms/src/main/resources/templates/admin/cmsDiy/preview.html. The manipulation of the argument url leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named c1e79f124e3f4c458315d908ed7dee06f9f12a76/f1af17af004ca9345c6fe4d5936d87d008d26e75. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sanluan PublicCMSto a version that resolves this vulnerability.Fixed in 5.202506.aPatch c1e79f124e3f4c458315d908ed7dee06f9f12a76/f1af17af004ca9345c6fe4d5936d87d008d26e75
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7949?
CVE-2025-7949 is classified as a problematic vulnerability in Sanluan PublicCMS.
How do I fix CVE-2025-7949?
To address CVE-2025-7949, update Sanluan PublicCMS to a version higher than 5.202506.a.
What are the potential impacts of CVE-2025-7949?
CVE-2025-7949 may lead to unauthorized access or manipulation of content within the affected functions of PublicCMS.
Which versions of Sanluan PublicCMS are affected by CVE-2025-7949?
CVE-2025-7949 affects all versions of Sanluan PublicCMS up to and including 5.202506.a.
Is there a workaround for CVE-2025-7949?
There is no documented workaround for CVE-2025-7949; upgrading is recommended for mitigation.