Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25654 | A vulnerability was found in HuangDou UTCMS 9. This issue affects some unknown processing of the file app/modules/ut-frame/admin/update.php of the component Config Handler. Performing manipulation of the argument UPDATEURL results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Utcms Project
Utcms Project utcms |
|
| CPEs | cpe:2.3:a:utcms_project:utcms:9.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Utcms Project
Utcms Project utcms |
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huangdou
Huangdou utcms |
|
| Vendors & Products |
Huangdou
Huangdou utcms |
Mon, 25 Aug 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in HuangDou UTCMS 9. This issue affects some unknown processing of the file app/modules/ut-frame/admin/update.php of the component Config Handler. Performing manipulation of the argument UPDATEURL results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | HuangDou UTCMS Config update.php server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-25T20:30:20.427Z
Reserved: 2025-08-24T14:52:36.289Z
Link: CVE-2025-9402
Updated: 2025-08-25T20:30:15.514Z
Status : Analyzed
Published: 2025-08-25T02:15:31.760
Modified: 2025-10-31T14:02:17.580
Link: CVE-2025-9402
No data.
OpenCVE Enrichment
Updated: 2025-08-25T09:05:24Z
EUVD