CVE-2025-15375 is a critical deserialization vulnerability affecting EyouCMS versions up to 1.7.7, specifically within the arcpagelist Handler in the application/api/controller/Ajax.php file. By manipulating the 'attstr' argument, an authenticated attacker can remotely trigger deserialization, leading to a CVSSv3.1 score of 8.8 (High) due to potential for complete compromise of confidentiality, integrity, and availability. While the vendor has acknowledged the flaw and plans a fix in version 1.7.8, exploit code has been publicly released, increasing the immediate risk of exploitation. Despite the public exploit, there is currently no evidence of active exploitation, and community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.8CPE matchmatch criteria | cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.