CVE-2025-5402
Last modified
CVE-2025-5402 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as critical. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/includes/edit_post.php of the component GET Parameter Handler. The manipulation of the argument edit_post_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chaitak-Gorai | Blogbook | <= 2021-11-22 |
References
- https://vuldb.com/?ctiid.310742Permissions Required, VDB Entry
- https://vuldb.com/?id.310742Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.582904Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5402?
How severe is CVE-2025-5402?
How do I fix CVE-2025-5402?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54014Deserialization of Untrusted Data vulnerability in QuanticaL…9.8
- CVE-2025-54015Improper Control of Filename for Include/Require Statement i…6.6
- CVE-2025-54016Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-54017Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-54018Missing Authorization vulnerability in CreativeMindsSolution…4.3
- CVE-2025-54019Improper Control of Generation of Code ('Code Injection') vu…6.5
- CVE-2025-54020Cross-Site Request Forgery (CSRF) vulnerability in Erik Anti…5.4
- CVE-2025-54021Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2025-54022Cross-Site Request Forgery (CSRF) vulnerability in Elliot So…6.5
- CVE-2025-54023Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-54024Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-54025Missing Authorization vulnerability in Elliot Sowersby / Rel…6.5
Are you affected by CVE-2025-5402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
