PT-2025-33436 · Mtons · Mtons Mblog
Zast.Ai
·
Published
2025-08-15
·
Updated
2025-08-18
·
CVE-2025-9005
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
mtons mblog versions prior to 3.5.1
Description:
A vulnerability exists in mtons mblog up to version 3.5.0. The issue affects an unknown function within the
/register endpoint and leads to information exposure through error messages. The attack can be launched remotely, but is considered to have relatively high complexity and difficult exploitability. The exploit has been publicly disclosed and may be used.Recommendations:
Update mtons mblog to version 3.5.1 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mtons Mblog