CVE-2025-15589

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://gist.github.com/b1uel0n3/275ac353537ecf4c8973d33fa0d5b0fe Exploit Third Party Advisory
https://gist.github.com/b1uel0n3/275ac353537ecf4c8973d33fa0d5b0fe#proof-of-concept Exploit Third Party Advisory
https://vuldb.com/?ctiid.336710 Permissions Required VDB Entry
https://vuldb.com/?id.336710 Third Party Advisory VDB Entry
https://vuldb.com/?submit.702489 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:muyucms:muyucms:2.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-24 06:16

Updated : 2026-06-17 08:38


NVD link : CVE-2025-15589

Mitre link : CVE-2025-15589

CVE.ORG link : CVE-2025-15589


JSON object : View

Products Affected

muyucms

  • muyucms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')