Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28607 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 22 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dogukanurker
Dogukanurker flaskblog |
|
| Vendors & Products |
Dogukanurker
Dogukanurker flaskblog |
Tue, 19 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file. | |
| Title | flaskBlog allows arbitrary privilege escalation | |
| Weaknesses | CWE-425 CWE-807 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-19T19:29:09.500Z
Reserved: 2025-08-14T22:31:17.683Z
Link: CVE-2025-55736
Updated: 2025-08-19T19:28:58.842Z
Status : Analyzed
Published: 2025-08-19T19:15:37.837
Modified: 2025-08-22T20:56:14.600
Link: CVE-2025-55736
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:31:55Z
EUVD