CVE-2025-8546 Information

Description

A vulnerability which was classified as problematic was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf. It is recommended to apply a patch to fix this issue.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf https://github.com/atjiu/pybbs/issues/199 https://github.com/atjiu/pybbs/issues/199#issue-3256276118 https://github.com/atjiu/pybbs/issues/199#issuecomment-3134573731 https://vuldb.com/?ctiid.318675 https://vuldb.com/?id.318675 https://vuldb.com/?submit.622179

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

CNNVD-202508-307 (Published: 2025-08-05)

Share on: