PT-2025-31906 · Unknown · Atjiu Pybbs
Zast.Ai
·
Published
2025-08-05
·
Updated
2025-08-05
·
CVE-2025-8548
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
atjiu pybbs versions prior to 6.0.0
Description
A problematic issue exists in the Registered Email Handler component of atjiu pybbs. This issue affects the
sendEmailCode function within the src/main/java/co/yiiu/pybbs/controller/api/SettingsApiController.java file. Manipulation of the email argument can lead to information exposure through an error message. The attack can be initiated remotely and is considered complex to exploit. The exploit has been publicly disclosed and may be used.Recommendations
Apply a patch with identifier 234197c4f8fc7ce24bdcff5430cd42492f28936a to resolve this issue.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atjiu Pybbs