An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
2025-01-27T23:15:09.723
2025-06-27T19:03:32.293
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | youdiancms | youdiancms | ≤ 9.5.20 | Yes |