GHSA-7hrx-vv78-95j8MediumCVSS 4.3

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add...

Published
September 11, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (1)

📋 Description

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.

🔗 References (7)