PT-2026-21193 · Smanga · Smanga

CVE-2025-70833

·

Publicado

2026-02-20

·

Atualizado

2026-02-23

CVSS v3.1

9.4

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Smanga version 3.2.7
Description An authentication bypass exists in Smanga version 3.2.7. An unauthenticated attacker can reset the password of any user, including the administrator, and fully compromise the account. This is achieved by manipulating POST parameters within the check-power.php file, due to insecure permission validation. The vulnerable component is the check-power.php file.
Recommendations Update to a newer version of Smanga that addresses this issue. As a temporary workaround, restrict access to the check-power.php file.

Exploit

Correção

IDOR

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-70833

Produtos afetados

Smanga