CVE-2015-1578: Yuba u5cms
Medium severity, CVSS 5.8. EPSS: 7.2% chance of exploitation in the next 30 days.
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php.
Affected products
- Yuba u5cms: up to and including 3.9.3
Published 2015-02-11. Last modified 2026-06-17.