PT-2025-33435 · Mtons · Mtons Mblog
Zast.Ai
·
Published
2025-08-15
·
Updated
2025-08-27
·
CVE-2025-9004
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
mtons mblog versions prior to 3.5.1
Description:
A vulnerability was found in mtons mblog up to version 3.5.0. This issue affects some unknown processing of the file
/settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely and has a rather high complexity. Exploitation is known to be difficult, and the exploit has been disclosed to the public.Recommendations:
Update mtons mblog to version 3.5.1 or later.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mtons Mblog