Anjoy8 · Blog.Core · CVE-2026-30689
**Name of the Vulnerable Software and Affected Versions**
Blog.Core versions prior to bcb4d17
**Description**
The 'getinfobytoken' API endpoint contains improper access control, which allows unauthorized parties to obtain sensitive administrator account information by using a valid token. This issue leads to sensitive data exposure and threatens system security.
**Recommendations**
Update Blog.Core to a version later than bcb4d17.
As a temporary mitigation, restrict access to the 'getinfobytoken' API endpoint.