PT-2026-21193 · Smanga · Smanga
CVE-2025-70833
·
Publicado
2026-02-20
·
Atualizado
2026-02-23
CVSS v3.1
9.4
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Smanga version 3.2.7
Description
An authentication bypass exists in Smanga version 3.2.7. An unauthenticated attacker can reset the password of any user, including the administrator, and fully compromise the account. This is achieved by manipulating POST parameters within the
check-power.php file, due to insecure permission validation. The vulnerable component is the check-power.php file.Recommendations
Update to a newer version of Smanga that addresses this issue. As a temporary workaround, restrict access to the
check-power.php file.Exploit
Correção
IDOR
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Smanga