No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28632 | The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2. |
Tue, 26 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2. | |
| Title | The Scratch Channel's Publish Articles POST Request Can Upload Articles Without Validation | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-26T19:09:47.842Z
Reserved: 2025-08-20T14:30:35.009Z
Link: CVE-2025-57805
Updated: 2025-08-26T19:06:48.131Z
Status : Deferred
Published: 2025-08-25T22:15:33.087
Modified: 2026-06-17T09:43:28.160
Link: CVE-2025-57805
No data.
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation
EUVD