3.7

CVE-2025-8549

Exploit

atjiu pybbs UserAdminController.java update weak password

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. The manipulation leads to weak password requirements. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as d09cb19a8e7d7e5151282926ada54080244d499f. It is recommended to apply a patch to fix this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pybbs ProjectPybbs Version <= 6.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.314
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 2.9 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
cna@vuldb.com 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-521 Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

https://vuldb.com/?id.318678
Third Party Advisory
VDB Entry
https://vuldb.com/?ctiid.318678
VDB Entry
Permissions Required
https://vuldb.com/?submit.622187
Third Party Advisory
VDB Entry
https://github.com/atjiu/pybbs/issues/201
Exploit
Issue Tracking
https://github.com/atjiu/pybbs/issues/201#issuecomment-3134733216
Issue Tracking
https://github.com/atjiu/pybbs/issues/201#issue-3256288016
Exploit
Issue Tracking
https://github.com/atjiu/pybbs/commit/d09cb19a8e7d7e5151282926ada54080244d499f
Patch