Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25126

Опубликовано: 29 янв. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (POST /api/v1/forum/vote) trusts the JSON body’s direction value without runtime validation. TypeScript types are not enforced at runtime, so an attacker can send arbitrary strings (e.g., "x") as direction. Downstream (VoteServer) treats any non-"up" and non-null value as a downvote and persists the invalid value in votes_data. This can be exploited to bypass intended business logic. Version 0-PRERELEASE-15 fixes the vulnerability.

EPSS

Процентиль: 12%
0.0004
Низкий

7.1 High

CVSS3

Дефекты

CWE-20

EPSS

Процентиль: 12%
0.0004
Низкий

7.1 High

CVSS3

Дефекты

CWE-20