CVE Vulnerabilities

CVE-2025-55736

Direct Request ('Forced Browsing')

Published: Aug 19, 2025 | Modified: Aug 22, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to admin, giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Flaskblog Dogukanurker * 2.8.0 (including)

Potential Mitigations

References