Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28846 | A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument code leads to incorrect comparison. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Utcms Project
Utcms Project utcms |
|
| CPEs | cpe:2.3:a:utcms_project:utcms:9.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Utcms Project
Utcms Project utcms |
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huangdou
Huangdou utcms |
|
| Vendors & Products |
Huangdou
Huangdou utcms |
Mon, 25 Aug 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument code leads to incorrect comparison. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | HuangDou UTCMS Login login.php comparison | |
| Weaknesses | CWE-697 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-25T20:29:38.215Z
Reserved: 2025-08-24T14:52:33.683Z
Link: CVE-2025-9401
Updated: 2025-08-25T20:29:32.808Z
Status : Analyzed
Published: 2025-08-25T01:15:36.930
Modified: 2025-10-31T13:58:30.063
Link: CVE-2025-9401
No data.
OpenCVE Enrichment
Updated: 2025-08-25T09:05:25Z
EUVD