ZeroHour

CVE-2025-70833

CVSS 3.1
9.4 critical
EPSS
<1%p33
Published
()
Modified
Description

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

Vendors
lkw199711
Products
smanga
Weakness
CWE-287, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.