CVE-2025-13813 is a missing authorization vulnerability in moxi159753 Mogu Blog v2 up to version 5.2, specifically affecting the Storage Management Endpoint's /storage/ file processing. Rated 8.1 HIGH on CVSS, this remotely exploitable flaw has high attack complexity but could lead to full confidentiality, integrity, and availability compromise. While an exploit is publicly available, its difficult exploitability and lack of active exploitation, Metasploit/Nuclei modules, or significant community discussion suggest limited current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2CPE matchmatch criteria | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.