CVE Details
Basic Information
| Title |
quequnlong shiyi-blog photos improper authorization |
| Type |
cve |
| Published |
2025-06-03T17:00:19.488Z |
| Last Seen |
|
Product Information
| Vendor |
quequnlong |
| Product |
shiyi-blog |
| Version |
1.2.0 |
CVSS Information
| Base Score |
6.9 (MEDIUM) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A critical vulnerability in quequnlong shiyi-blog up to version 1.2.1 allows improper authorization, enabling remote attackers to access photo albums without proper permissions. This issue has a CVSS score of 6.9, indicating a medium severity level. |
| AI Severity |
Medium |
| Vendor |
quequnlong |
| Product |
shiyi-blog |
| Affected Version |
1.2.0, 1.2.1 |
Additional Information
| CVE List |
|
| CWE List |
CWE-285, CWE-266 |
| Bulletin Family |
|
| Source Data |
quequnlong shiyi-blog 1.2.0
quequnlong shiyi-blog 1.2.1 |
Source Information
| Source Data |
quequnlong shiyi-blog 1.2.0
quequnlong shiyi-blog 1.2.1 |
| Source Link |
|
Description
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score Summary
View Full CVE Details