CVE-2025-11904 describes a high-severity SQL injection vulnerability in ChanCMS versions up to 3.3.2, specifically within the hasUse function of the /cms/model/hasUse file. An attacker can remotely exploit this by manipulating the 'ID' argument, potentially leading to full compromise of confidentiality, integrity, and availability. While the vendor has not responded to disclosure, public exploit code exists, making this a significant risk despite no evidence of active exploitation or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.2CPE matchmatch criteria | cpe:2.3:a:chancms:chancms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.