We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-8838

WinterChenS my-site Backend admin preHandle improper authentication



Description

EN DE

A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argument uri leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The code maintainer responded to the issue that "[he] tried it, and using this link automatically redirects to the login page."

Betroffen ist die Funktion preHandle der Datei /admin/ der Komponente Backend Interface. Durch das Beeinflussen des Arguments uri mit unbekannten Daten kann eine improper authentication-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung. Zur Zeit ist nicht genau klar, ob diese Schwachstelle in der besagten Form wirklich existiert. Dieses Produkt verzichtet auf eine Versionierung und verwendet stattdessen Rolling Releases. Deshalb sind keine Details zu betroffenen oder zu aktualisierende Versionen vorhanden.

Reserved 2025-08-10 | Published 2025-08-11 | Updated 2025-08-11 | Assigner VulDB


MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR

Problem types

Improper Authentication

Product status

1f7525f15934d9d6a278de967f6ec9f1757738d8
affected

Timeline

2025-08-10:Advisory disclosed
2025-08-10:VulDB entry created
2025-08-10:VulDB entry last update

Credits

fushuling (VulDB User) reporter

References

vuldb.com/?id.319372 (VDB-319372 | WinterChenS my-site Backend admin preHandle improper authentication) vdb-entry technical-description

vuldb.com/?ctiid.319372 (VDB-319372 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.622421 (Submit #622421 | WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8 Incorrect Access Control) third-party-advisory

github.com/WinterChenS/my-site/issues/97 issue-tracking

github.com/WinterChenS/my-site/issues/97 issue-tracking

github.com/WinterChenS/my-site/issues/97 exploit issue-tracking

cve.org (CVE-2025-8838)

nvd.nist.gov (CVE-2025-8838)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-8838

Support options

Helpdesk Chat, Email, Knowledgebase