CVE Vulnerabilities

CVE-2025-50904

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 20, 2025 | Modified: Sep 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
My-site Winterchens * 2025-06-11 (including)

Potential Mitigations

References