A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf | Patch |
https://github.com/atjiu/pybbs/issues/199 | Exploit Issue Tracking |
https://github.com/atjiu/pybbs/issues/199#issue-3256276118 | Exploit Issue Tracking |
https://github.com/atjiu/pybbs/issues/199#issuecomment-3134573731 | Issue Tracking |
https://vuldb.com/?ctiid.318675 | Permissions Required VDB Entry |
https://vuldb.com/?id.318675 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.622179 | Third Party Advisory VDB Entry |
Configurations
History
03 Sep 2025, 14:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf - Patch | |
References | () https://github.com/atjiu/pybbs/issues/199 - Exploit, Issue Tracking | |
References | () https://github.com/atjiu/pybbs/issues/199#issue-3256276118 - Exploit, Issue Tracking | |
References | () https://github.com/atjiu/pybbs/issues/199#issuecomment-3134573731 - Issue Tracking | |
References | () https://vuldb.com/?ctiid.318675 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.318675 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.622179 - Third Party Advisory, VDB Entry | |
First Time |
Pybbs Project pybbs
Pybbs Project |
|
CPE | cpe:2.3:a:pybbs_project:pybbs:*:*:*:*:*:*:*:* |
05 Aug 2025, 14:34
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
05 Aug 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-05 05:15
Updated : 2025-09-03 14:00
NVD link : CVE-2025-8546
Mitre link : CVE-2025-8546
CVE.ORG link : CVE-2025-8546
JSON object : View
Products Affected
pybbs_project
- pybbs