First published: Mon Apr 21 2025(Updated: )
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
laskBlog |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28103 has been classified as a critical severity vulnerability due to its potential to allow unauthorized account deletions.
To fix CVE-2025-28103, update to the latest version of laskBlog where the access control issue has been addressed.
Exploiting CVE-2025-28103 could lead to complete account loss for users as attackers can delete user accounts without authorization.
CVE-2025-28103 affects laskBlog version 2.6.1 specifically.
CVE-2025-28103 is an access control vulnerability that allows attackers to perform unauthorized actions.