CVE-2025-2491 | Dromara ujcms 9.7.5 Edit Template File Page WebFileTemplateController.java update Cross site scripting (Issue 14)
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to Cross site scripting.
This vulnerability is uniquely identified as CVE-2025-2491. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.