---
id: CVE-2025-15173
title: A weakness has been identified in SohuTV CacheCloud up to 3.2.0
summary: >-
  A weakness has been identified in SohuTV CacheCloud up to 3.2.0. Affected is
  the function advancedAnalysis of the file
  src/main/java/com/sohu/cache/web/controller/InstanceController.java. This
  manipulation causes cross site scripting. Th…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: sohu
product: cachecloud
affected:
  - cachecloud <= 3.2
published: '2025-12-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T12:10:00.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15173'
references:
  - url: 'https://github.com/sohutv/cachecloud/issues/369'
    label: cna@vuldb.com
  - url: 'https://github.com/sohutv/cachecloud/issues/369#issue-3733560985'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338558'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338558'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.716307'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.13635
ingestedAt: '2026-10-07T12:29:01.327Z'
---

## Overview

A weakness has been identified in SohuTV CacheCloud up to 3.2.0. Affected is the function advancedAnalysis of the file src/main/java/com/sohu/cache/web/controller/InstanceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The project was informed of the problem early through an issue report but has not responded yet.

## Affected

- `cachecloud <= 3.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
