CVE 5.1 MEDIUM

atjiu pybbs IndexController.java changeLanguage redirect_CVE-2025-8813

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This vulnerability affects the function changeLanguage of the file src/main/java/co/yiiu/pybbs/controller/front/IndexController.java. The manipulation of the argument referer leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as edb14ff13e9e05394960ba46c3d31d844ff2deac. It is recommended to apply a patch to fix this issue.

AI Analysis

A vulnerability in the changeLanguage function of atjiu pybbs allows remote attackers to perform open redirect attacks via the referer argument. A patch is available to fix this issue.

Basic Information

ID CVE-2025-8813
Source VulDB
Published Aug 10, 2025 at 14:32

Affected Product

Vendor atjiu
Product pybbs
Version 6.0
Affected Versions atjiu pybbs 6.0

CWE Classification

AI Assessment

AI Severity Medium
Vendor atjiu
Product pybbs
Version 6.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.