Description
A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file src/main/java/com/sohu/cache/web/controller/WebResourceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
https://github.com/sohutv/cachecloud/issues/373
https://vuldb.com/?ctiid.338588
https://vuldb.com/?submit.716312
https://github.com/sohutv/cachecloud/issues/373
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
3.5 · Low
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-12-29T19:15:56.370Z
2 weeks agoLast modified
2026-01-06T21:37:32.140Z
1 week ago