Impact
The vulnerability stems from MoguBlog’s comment posting endpoint failing to validate that the userUid supplied in the request body matches the authenticated user. As a result, any logged‑in user can submit a comment with an arbitrary userUid, causing the comment to appear as though it was authored by another account, including administrators. This flaw is an instance of improper authorization and is classified as CWE‑639.
Affected Systems
MoguBlog versions 6.2 and earlier are affected. The flaw exists in the CommentRestApi handling within the mogu_web module, specifically the POST /web/comment/add endpoint. Any installation running these releases can be exploited if the user is authenticated.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate overall risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Exploitation requires an authenticated session; unauthenticated users cannot provide a valid session token. The attacker can construct a POST payload and set any userUid value, resulting in impersonated comments that may be used to defame or misrepresent an account. The impact is limited to reputational damage and unauthorized content attribution rather than privilege escalation or system compromise.
OpenCVE Enrichment