CVE-2025-60319

PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).
Configurations

Configuration 1 (hide)

cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*

History

09 Dec 2025, 18:28

Type Values Removed Values Added
CPE cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*
First Time Perfree
Perfree perfreeblog
References () https://github.com/PerfreeBlog/PerfreeBlog/commit/103c79165e3a41a1729188fdc8a1e90c97c0a06d - () https://github.com/PerfreeBlog/PerfreeBlog/commit/103c79165e3a41a1729188fdc8a1e90c97c0a06d - Patch
References () https://github.com/PerfreeBlog/PerfreeBlog/issues/20 - () https://github.com/PerfreeBlog/PerfreeBlog/issues/20 - Issue Tracking, Patch, Vendor Advisory

30 Oct 2025, 21:15

Type Values Removed Values Added
CWE CWE-918
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

30 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 17:15

Updated : 2025-12-09 18:28


NVD link : CVE-2025-60319

Mitre link : CVE-2025-60319

CVE.ORG link : CVE-2025-60319


JSON object : View

Products Affected

perfree

  • perfreeblog
CWE
CWE-918

Server-Side Request Forgery (SSRF)