GHSA-7vp6-9cc5-c2c2HighCVSS 7.5

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion...

Published
September 11, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (1)

📋 Description

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

🔗 References (8)