CVE-2025-28104

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Apr 21, 2025
Updated: May 12, 2025
CWE ID 284

Summary

CVE-2025-28104 is a newly disclosed vulnerability affecting the laskBlog v2.6.1 software. The issue stems from an incorrect access control mechanism, which allows unauthorized access to usernames. An attacker can exploit this vulnerability by providing a crafted input, granting them access to all usernames in the system. This vulnerability poses a significant risk, as attackers could potentially use obtained usernames for further exploitation or unauthorized system actions. It is recommended that users update their laskBlog software to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share