PT-2025-33839 · Unknown · Thrivex-Blog
Echo0D
·
Published
2025-08-19
·
Updated
2025-08-19
·
CVE-2025-9151
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
LiuYuYang01 ThriveX-Blog versions through 3.1.7
Description:
A security flaw exists in the
updateJsonValueByName function within the /web config/json/name/web file. This flaw results in improper authorization and allows for remote attacks. The exploit for this issue has been publicly released. The vendor was notified of this disclosure but did not respond.Recommendations:
Update to a version beyond 3.1.7.
As a temporary workaround, consider restricting access to the
/web config/json/name/web file.
Disable or restrict the use of the updateJsonValueByName function until a patch is available.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thrivex-Blog