CVE-2025-8548
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic.
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiController.java of the component Registered Email Handler. The manipulation of the argument email leads to information exposure through error message. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 234197c4f8fc7ce24bdcff5430cd42492f28936a. It is recommended to apply a patch to fix this issue.
- CVSS 4.0
- 2.9 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-209
- Affected
- pybbs project/pybbs
- Source
- cna@vuldb.com
References
- https://github.com/atjiu/pybbs/commit/234197c4f8fc7ce24bdcff5430cd42492f28936aPatch
- https://github.com/atjiu/pybbs/issues/202Exploit, Issue Tracking
- https://github.com/atjiu/pybbs/issues/202#issue-3256293499Exploit, Issue Tracking
- https://github.com/atjiu/pybbs/issues/202#issuecomment-3134602615Issue Tracking
- https://vuldb.com/?ctiid.318677Permissions Required, VDB Entry
- https://vuldb.com/?id.318677Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.622186Third Party Advisory, VDB Entry
- https://github.com/atjiu/pybbs/issues/202Exploit, Issue Tracking
- https://github.com/atjiu/pybbs/issues/202#issue-3256293499Exploit, Issue Tracking
- https://github.com/atjiu/pybbs/issues/202#issuecomment-3134602615Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.