---
id: CVE-2025-15422
title: A flaw has been found in EmpireSoft EmpireCMS up to 8.0
summary: >-
  A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects
  the function egetip of the file e/class/connect.php of the component IP
  Address Handler. This manipulation causes protection mechanism failure. The
  attack may be…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-693
vendor: phome
product: empirecms
affected:
  - empirecms <= 8.0
published: '2026-01-02'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15422'
references:
  - url: 'https://note-hxlab.wetolink.com/share/0x74KEtzecFb'
    label: cna@vuldb.com
  - url: >-
      https://note-hxlab.wetolink.com/share/0x74KEtzecFb#-span--strong-proof-of-concept---strong---span-
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.339344'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.339344'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.721344'
    label: cna@vuldb.com
  - url: 'https://note-hxlab.wetolink.com/share/0x74KEtzecFb'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://note-hxlab.wetolink.com/share/0x74KEtzecFb#-span--strong-proof-of-concept---strong---span-
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01266
epssPercentile: 0.68583
ingestedAt: '2026-10-01T08:40:11.728Z'
---

## Overview

A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `empirecms <= 8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
