A template injection vulnerability in the /vip/v1/file...
Critical severity
Unreviewed
Published
Dec 10, 2025
to the GitHub Advisory Database
•
Updated Dec 18, 2025
Description
Published by the National Vulnerability Database
Dec 10, 2025
Published to the GitHub Advisory Database
Dec 10, 2025
Last updated
Dec 18, 2025
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
References