CVE-2025-8838 describes an improper authentication vulnerability in the Backend Interface component of WinterChenS my-site, affecting versions up to commit 1f7525f15934d9d6a278de967f6ec9f1757738d8. By manipulating the 'uri' argument in the preHandle function of the /admin/ path, an unauthenticated attacker can bypass security controls. This critical vulnerability, rated 9.8 CVSS, allows for remote exploitation with high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed and community discussion is high, its real-world existence is currently doubted by the maintainer, and there is no evidence of active exploitation or readily available exploit tools like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025-06-11CPE matchmatch criteria | cpe:2.3:a:winterchens:my-site:2025-06-11:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.