---
id: CVE-2025-15094
title: >-
  A weakness has been identified in sunkaifei FlyCMS up to
  abbaa5a8daefb146ad4d61027035026b052cb414
summary: >-
  A weakness has been identified in sunkaifei FlyCMS up to
  abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function
  userLogin of the file src/main/java/com/flycms/web/front/UserController.java
  of the component User Lo…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: sunkaifei
product: flycms
affected:
  - flycms <= 2019-12-20
published: '2025-12-26'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15094'
references:
  - url: 'https://github.com/sunkaifei/FlyCms/'
    label: cna@vuldb.com
  - url: 'https://github.com/sunkaifei/FlyCms/issues/16'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338423'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338423'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.708997'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00394
epssPercentile: 0.31163
ingestedAt: '2026-09-30T23:29:32.512Z'
---

## Overview

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

## Affected

- `flycms <= 2019-12-20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
