6.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is assessed as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2025-13813
Source
VulDB
Published
Dec 1, 2025 at 07:02
Affected Product
Vendor
moxi159753
Product
Mogu Blog v2
Version
5.0
Affected Versions
moxi159753 Mogu Blog v2 5.0
moxi159753 Mogu Blog v2 5.1
moxi159753 Mogu Blog v2 5.2
moxi159753 Mogu Blog v2 5.1
moxi159753 Mogu Blog v2 5.2