PT-2025-33436 · Mtons · Mtons Mblog

Zast.Ai

·

Published

2025-08-15

·

Updated

2025-08-18

·

CVE-2025-9005

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: mtons mblog versions prior to 3.5.1
Description: A vulnerability exists in mtons mblog up to version 3.5.0. The issue affects an unknown function within the /register endpoint and leads to information exposure through error messages. The attack can be launched remotely, but is considered to have relatively high complexity and difficult exploitability. The exploit has been publicly disclosed and may be used.
Recommendations: Update mtons mblog to version 3.5.1 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-9005

Affected Products

Mtons Mblog