CVE-2025-3532 | YouDianCMS 9.5.21 index.html.Attackers OrderNumber cross site scripting
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App/Tpl/Member/Default/Order/index.html.Attackers. The manipulation of the argument OrderNumber leads to cross site scripting.
This vulnerability was named CVE-2025-3532. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.