High severity8.6NVD Advisory· Published Apr 2, 2024· Updated Jun 17, 2026
CVE-2024-25187
CVE-2024-25187
Description
Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:xiaocheng-keji:71cms:1.0:*:*:*:*:*:*:*
- 71cms/71cmsdescription
Patches
Vulnerability mechanics
References
2- github.com/xiaocheng-keji/71cms/issues/2nvdBroken LinkExploit
- gist.github.com/wisejayer/d365e93ce09b8a36641165e1d1a0a06cnvdThird Party Advisory
News mentions
0No linked articles in our index yet.