Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Dec 18, 2025
CVE-2025-65602
CVE-2025-65602
Description
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
Affected products
2- ChanCMS/ChanCMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.