A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
Title | ChanCMS search sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-08T22:32:09.780Z
Reserved: 2025-09-08T14:15:33.950Z
Link: CVE-2025-10110

No data.

Status : Received
Published: 2025-09-08T23:15:34.600
Modified: 2025-09-08T23:15:34.600
Link: CVE-2025-10110

No data.

No data.