---
id: CVE-2025-11904
title: A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2
summary: >-
  A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This
  affects the function hasUse of the file /cms/model/hasUse. The manipulation of
  the argument ID leads to sql injection. The attack may be initiated remotely.
  The exp…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: chancms
product: chancms
affected:
  - chancms <= 3.3.2
published: '2025-10-17'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11904'
references:
  - url: >-
      https://github.com/NarcherAlter/Security_Note/blob/main/Vulnerability_Discovery/ChanCMSv3.3.2.md#222
    label: cna@vuldb.com
  - url: >-
      https://github.com/NarcherAlter/Security_Note/blob/main/Vulnerability_Discovery/ChanCMSv3.3.2.md#cmsmodelhasuse
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328914'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328914'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.670274'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00633
epssPercentile: 0.48736
ingestedAt: '2026-10-09T12:53:29.115Z'
---

## Overview

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `chancms <= 3.3.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
