PT-2025-31906 · Unknown · Atjiu Pybbs

Zast.Ai

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-8548

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions atjiu pybbs versions prior to 6.0.0
Description A problematic issue exists in the Registered Email Handler component of atjiu pybbs. This issue affects the sendEmailCode function within the src/main/java/co/yiiu/pybbs/controller/api/SettingsApiController.java file. Manipulation of the email argument can lead to information exposure through an error message. The attack can be initiated remotely and is considered complex to exploit. The exploit has been publicly disclosed and may be used.
Recommendations Apply a patch with identifier 234197c4f8fc7ce24bdcff5430cd42492f28936a to resolve this issue.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-8548

Affected Products

Atjiu Pybbs