flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 19 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file. | |
Title | flaskBlog allows arbitrary privilege escalation | |
Weaknesses | CWE-425 CWE-807 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-19T19:04:00.564Z
Updated: 2025-08-19T19:29:09.500Z
Reserved: 2025-08-14T22:31:17.683Z
Link: CVE-2025-55736

Updated: 2025-08-19T19:28:58.842Z

Status : Awaiting Analysis
Published: 2025-08-19T19:15:37.837
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-55736

No data.