PT-2025-47870 · Code Projects · Eblog Site

Yohane-Mashiro

·

Published

2025-11-24

·

Updated

2025-12-02

·

CVE-2025-13576

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Blog Site version 1.0
Description A security issue exists in code-projects Blog Site 1.0 where manipulation of an unknown function within the /admin.php file can lead to improper authorization. This allows for remote initiation of the attack. The exploit is publicly available. Multiple API endpoints are affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13576

Affected Products

Eblog Site