CVE-2025-10674: fuyang_lipengjun platform queryAll AttributeCategoryController improper authorization
A vulnerability was identified in fuyanglipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10674?
CVE-2025-10674 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-10674?
To mitigate CVE-2025-10674, disable the affected function or implement proper authorization checks in the AttributeCategoryController.
Which software is affected by CVE-2025-10674?
CVE-2025-10674 affects the fuyang_lipengjun platform version 1.0.
Can CVE-2025-10674 be exploited remotely?
Yes, CVE-2025-10674 can be exploited remotely, allowing attackers to manipulate the affected component.
What type of vulnerability is CVE-2025-10674?
CVE-2025-10674 is an improper authorization vulnerability that allows unauthorized users to access restricted functionalities.