CVE-2025-10821 describes an improper authorization vulnerability in the fuyang_lipengjun platform version 1.0, specifically within the TopicCategoryController function of the /topiccategory/queryAll file. This flaw allows a remote attacker with low privileges to bypass authorization checks, potentially leading to unauthorized access to sensitive information. While the CVSS score is 4.3 (Medium), indicating a low impact on confidentiality, an exploit has been published, increasing the immediate risk. Despite the public exploit, there is currently no evidence of active exploitation, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:fuyang_lipengjun:platform:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.