A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/zhangyd-c/OneBlog/issues/35 | Exploit Issue Tracking |
https://github.com/zhangyd-c/OneBlog/issues/35 | Exploit Issue Tracking |
https://github.com/zhangyd-c/OneBlog/issues/35#issue-2914268214 | Exploit Issue Tracking |
https://github.com/zhangyd-c/OneBlog/issues/35#issue-2914268214 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.301470 | Permissions Required VDB Entry |
https://vuldb.com/?id.301470 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.521813 | Third Party Advisory VDB Entry |
Configurations
History
01 Apr 2025, 15:43
Type | Values Removed | Values Added |
---|---|---|
First Time |
Zhyd
Zhyd oneblog |
|
CPE | cpe:2.3:a:zhyd:oneblog:*:*:*:*:*:*:*:* | |
References | () https://vuldb.com/?id.301470 - Third Party Advisory, VDB Entry | |
References | () https://github.com/zhangyd-c/OneBlog/issues/35#issue-2914268214 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.301470 - Permissions Required, VDB Entry | |
References | () https://github.com/zhangyd-c/OneBlog/issues/35 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?submit.521813 - Third Party Advisory, VDB Entry |
27 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
27 Mar 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-27 04:15
Updated : 2025-04-01 15:43
NVD link : CVE-2025-2833
Mitre link : CVE-2025-2833
JSON object : View
Products Affected
zhyd
- oneblog
CWE
No CWE.