PT-2025-32531 · Winterchens · My-Site
Fushuling
·
Publicado
2025-08-11
·
Atualizado
2025-08-16
·
CVE-2025-8838
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WinterChenS my-site (affected versions not specified)
Description:
A vulnerability exists in the
preHandle function of the /admin/ file within the Backend Interface component. Manipulation of the uri argument results in improper authentication. The attack can be initiated remotely. The exploit has been disclosed publicly. The existence of this vulnerability is currently doubted. The product utilizes a rolling release model, and therefore, specific version details for affected or updated releases are unavailable. The code maintainer reported that accessing the vulnerable link automatically redirects to the login page.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
My-Site