CVE-2025-10086
fuyang_lipengjun platform AdPositionController queryAll improper authorization
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. Affects another part than CVE-2025-9936.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
fuyang_lipengjun · platform¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →