CVE-2025-8547 is a critical improper authorization vulnerability affecting the Email Verification Handler component in atjiu pybbs up to version 6.0.0. This flaw allows remote attackers to manipulate the email verification process, potentially leading to unauthorized actions. While rated as MEDIUM severity (CVSS 5.3) due to its low impact on integrity and no impact on confidentiality or availability, the vulnerability is easily exploitable over the network without user interaction. A patch (044f22893bee254dc2bb0d30f614913fab3c22c2) has been released, and the exploit has been publicly disclosed, though there is no evidence of active exploitation, readily available exploit code in common frameworks, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.0CPE matchmatch criteria | cpe:2.3:a:pybbs_project:pybbs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.