CVE-2025-8838 Information

Description

A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argument uri leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. This product is using a rolling release to provide continious delivery. Therefore no version details for affected nor updated releases are available. The code maintainer responded to the issue that [he] tried it and using this link automatically redirects to the login page.\

Reference

https://github.com/WinterChenS/my-site/issues/97 https://github.com/WinterChenS/my-site/issues/97#issuecomment-2986947791 https://github.com/WinterChenS/my-site/issues/97#issuecomment-2987091571 https://vuldb.com/?ctiid.319372 https://vuldb.com/?id.319372 https://vuldb.com/?submit.622421 https://github.com/WinterChenS/my-site/issues/97 https://vuldb.com/?submit.622421 https://github.com/WinterChenS/my-site/issues/97#issuecomment-2987091571 https://github.com/WinterChenS/my-site/issues/97#issuecomment-2986947791

CNNVD-202508-919 (Published: 2025-08-11)

Share on: