CVE-2025-45529
HIGHDescription
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
Is your site exposed to CVE-2025-45529?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sscms | siteserver_cms |
References
Frequently Asked Questions
What is CVE-2025-45529? +
How severe is CVE-2025-45529? +
What products are affected by CVE-2025-45529? +
How do I check if I'm vulnerable to CVE-2025-45529? +
Related Vulnerabilities
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission …
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow …
The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from …
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or …
dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In …
Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file …