CVE-2025-28103
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Apr 21, 2025
Updated: May 12, 2025
CWE ID 862
Summary
CVE-2025-28103 is a vulnerability affecting laskBlog version 2.6.1. This issue stems from an inappropriate access control mechanism, which enables attackers to delete user accounts at will through specially crafted requests. The flaw poses a significant risk, as malicious actors could exploit it to disrupt services or cause unintended consequences. The vulnerability should be addressed promptly by updating to a secure version of the software to mitigate potential harm.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- flaskBlog