Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vp6-9cc5-c2c2

Опубликовано: 11 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

EPSS

Процентиль: 24%
0.00309
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
nvd
12 дней назад

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

EPSS

Процентиль: 24%
0.00309
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-639