A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor is "[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8".
We have discovered 1,103 live websites that are affected by CVE-2025-15373.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 1,103 live websites (18% of eyouCMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 8 versions ( 31% of all versions) |
| 123 websites | |
| 527 websites | |
| 221 websites | |
| 138 websites | |
| 46 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites |
| .com | 831 websites |
| .cn | 148 websites |
| .net | 50 websites |
| .com.cn | 33 websites |
| .org | 12 websites |
| .ca | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,*** | ||
| ********.com | **,*** | ||
| **.link | **,*** | ||
| *****.com | ***,*** | ||
| ********.com | ***,*** | ||
| *******.net | ***,*** | ||
| ******.com | ***,*** | ||
| ****.cn | ***,*** | ||
| ****.cn | ***,*** | ||
| *****.com | ***,*** |