CVE-2025-2491
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 18, 2025
CWE ID 276
Summary
CVE-2025-2491 is a newly disclosed vulnerability that affects the Dromara ujcms 9.7.5 software. The issue lies within the "update" function of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java. This vulnerability is classified as problematic and enables cross-site scripting attacks. An attacker can initiate the exploit remotely, making it a significant security concern. Public disclosure of the exploit increases the risk of its usage in cyber attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.