CVE-2025-2320
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-2320 is a newly disclosed critical vulnerability affecting the User Handler component in version e84f6f5 of the springboot-openai-chatgpt package. The issue lies in the 'submit' function of the '/api/blade-user/submit' endpoint, which results in improper authorization. This vulnerability can be exploited remotely, allowing unauthorized access. Although the vendor was contacted about the disclosure, no response has been received. The product employs rolling releases, making it difficult to pinpoint the affected and patched versions. The exploit for this vulnerability is now public, increasing the risk for potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Craftcms Craft Cms