CVE-2025-3398: lenve VBlog WebSecurityConfig.java configure access control
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3398?
CVE-2025-3398 is classified as critical due to the improper access controls it introduces.
How do I fix CVE-2025-3398?
To fix CVE-2025-3398, update lenve VBlog to a version higher than 1.0.0.
What type of access control issue does CVE-2025-3398 cause?
CVE-2025-3398 leads to improper access controls within the application.
Which versions of lenve VBlog are affected by CVE-2025-3398?
CVE-2025-3398 affects lenve VBlog versions up to and including 1.0.0.
What is the nature of the vulnerability in CVE-2025-3398?
CVE-2025-3398 allows manipulation of access controls in the configure function of the WebSecurityConfig.java file.