The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 25 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2. | |
Title | The Scratch Channel's Publish Articles POST Request Can Upload Articles Without Validation | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-26T19:09:47.842Z
Reserved: 2025-08-20T14:30:35.009Z
Link: CVE-2025-57805

Updated: 2025-08-26T19:06:48.131Z

Status : Awaiting Analysis
Published: 2025-08-25T22:15:33.087
Modified: 2025-08-26T13:41:58.950
Link: CVE-2025-57805

No data.

No data.