GHSA-x4mm-wg99-32fjHighCVSS 7.5
A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access...
🔗 CVE IDs covered (1)
📋 Description
A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-30689
- https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40
- https://github.com/anjoy8/Blog.Core
- http://blagadmin.com
- https://github.com/anjoy8/Blog.Core/blob/bcb4d17ccc71e206a0c2ff663faf4b399e19f687/Blog.Core.Api/Controllers/UserController.cs#L139-L140
- https://github.com/advisories/GHSA-x4mm-wg99-32fj