CVE-2025-5511: quequnlong shiyi-blog photos improper authorization
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5511?
CVE-2025-5511 is classified as a critical vulnerability.
How do I fix CVE-2025-5511?
To fix CVE-2025-5511, upgrade the quequnlong shiyi-blog software to version 1.2.2 or higher.
What type of vulnerability is CVE-2025-5511?
CVE-2025-5511 is an improper authorization vulnerability.
Can CVE-2025-5511 be exploited remotely?
Yes, CVE-2025-5511 can be exploited remotely.
Which software is affected by CVE-2025-5511?
CVE-2025-5511 affects quequnlong shiyi-blog versions up to and including 1.2.1.