Impact
The vulnerability allows remote actors to freely invoke POST endpoints that create, delete, or modify the search index exposed by MoguBlog versions up to 6.2. Because the endpoints lack authentication, an attacker can remove the entire index, delete individual documents, or inject malicious entries. The loss or corruption of the index directly prevents the blog’s search functionality from returning correct results, effectively disabling a core feature and potentially causing loss of business data integrity.
Affected Systems
Products impacted are the MoguBlog project (moxi624:MoguBlog) through version 6.2. All deployments that expose the mogu_search service with its Elasticsearch index management endpoints are vulnerable, regardless of whether the application is hosted on-premises or in the cloud.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, and the vulnerability is not included in the KEV catalog. Attackers likely exploit the flaw remotely by sending crafted POST requests to the unauthenticated endpoints; no special privileges or credentials are required. Because the flaw directly disables search, an attacker could achieve denial of service and potentially arbitrary data deletion within the index.
OpenCVE Enrichment