PT-2026-21193 · Smanga · Smanga

Published

2026-02-20

·

Updated

2026-02-23

·

CVE-2025-70833

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Smanga version 3.2.7
Description An authentication bypass exists in Smanga version 3.2.7. An unauthenticated attacker can reset the password of any user, including the administrator, and fully compromise the account. This is achieved by manipulating POST parameters within the check-power.php file, due to insecure permission validation. The vulnerable component is the check-power.php file.
Recommendations Update to a newer version of Smanga that addresses this issue. As a temporary workaround, restrict access to the check-power.php file.

Exploit

Fix

IDOR

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-70833

Affected Products

Smanga