CVE-2025-65868 Details
Description
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
A denial-of-service vulnerability has been identified in Eyoucms version 1.7.1, caused by XML external entity (XXE) injection. This issue allows remote attackers to disrupt server operations by sending crafted POST requests with an XML payload designed to exhaust CPU resources. The vulnerability requires the application to be in production mode, and can be exploited using tools like Burp Suite's Intruder module to send parallel, multi-threaded requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/weng-xianhu/eyoucms/issues/66 | CISA-ADP | ExploitIssue TrackingVendor Advisory |
| https://github.com/weng-xianhu/eyoucms/issues/66 | [email protected] | ExploitIssue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| eyoucms eyoucms | 1.7.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 16, 2025 | Initial Analysis | [email protected] |
| Dec 5, 2025 | CVE Modified | CISA-ADP |
| Dec 3, 2025 | New CVE Received | [email protected] |