PT-2025-32531 · Winterchens · My-Site

Fushuling

·

Published

2025-08-11

·

Updated

2025-08-16

·

CVE-2025-8838

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WinterChenS my-site (affected versions not specified)
Description: A vulnerability exists in the preHandle function of the /admin/ file within the Backend Interface component. Manipulation of the uri argument results in improper authentication. The attack can be initiated remotely. The exploit has been disclosed publicly. The existence of this vulnerability is currently doubted. The product utilizes a rolling release model, and therefore, specific version details for affected or updated releases are unavailable. The code maintainer reported that accessing the vulnerable link automatically redirects to the login page.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8838

Affected Products

My-Site