PT-2025-33839 · Unknown · Thrivex-Blog

Echo0D

·

Published

2025-08-19

·

Updated

2025-08-19

·

CVE-2025-9151

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: LiuYuYang01 ThriveX-Blog versions through 3.1.7
Description: A security flaw exists in the updateJsonValueByName function within the /web config/json/name/web file. This flaw results in improper authorization and allows for remote attacks. The exploit for this issue has been publicly released. The vendor was notified of this disclosure but did not respond.
Recommendations: Update to a version beyond 3.1.7. As a temporary workaround, consider restricting access to the /web config/json/name/web file. Disable or restrict the use of the updateJsonValueByName function until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-9151

Affected Products

Thrivex-Blog