PT-2025-32531 · Winterchens · My-Site

Fushuling

·

Publicado

2025-08-11

·

Atualizado

2025-08-16

·

CVE-2025-8838

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WinterChenS my-site (affected versions not specified)
Description: A vulnerability exists in the preHandle function of the /admin/ file within the Backend Interface component. Manipulation of the uri argument results in improper authentication. The attack can be initiated remotely. The exploit has been disclosed publicly. The existence of this vulnerability is currently doubted. The product utilizes a rolling release model, and therefore, specific version details for affected or updated releases are unavailable. The code maintainer reported that accessing the vulnerable link automatically redirects to the login page.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8838

Produtos afetados

My-Site