CVE-2024-25187: Xiaocheng-Keji 71cms
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html.
Affected products
- Xiaocheng-Keji 71cms: version 1.0 only
Published 2024-04-02. Last modified 2026-06-17.