VulnerabilityAnalyzed
CVE-2025-9461
A weakness has been identified in diyhi bbs up to 6.8.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes information disclosure. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-284
- Affected
- diyhi/bbs
- Source
- cna@vuldb.com
References
- https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e1.mdProduct
- https://vuldb.com/?ctiid.321296Permissions Required, VDB Entry
- https://vuldb.com/?id.321296Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.634295Third Party Advisory, VDB Entry
- https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e1.mdProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.