CVE-2025-31606

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 862

Summary

CVE-2025-31606 is a Missing Authorization vulnerability affecting SP Blog Designer from versions n/a through 1.0.0. Hackers can exploit incorrectly configured access control security levels in this software, potentially gaining unauthorized access to sensitive data or functionality. This issue may lead to serious consequences if not addressed promptly, including data breaches or unintended system modifications. Users are strongly advised to update their SP Blog Designer installations to the latest version, or to contact their vendor for a suitable workaround or patch to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share