Metrics
Affected Vendors & Products
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weijiang1994
Weijiang1994 blogin |
|
| Vendors & Products |
Weijiang1994
Weijiang1994 blogin |
Fri, 21 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-307 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 20 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1390 | |
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-20T00:00:00.000Z
Updated: 2025-11-21T14:39:39.545Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63807
Updated: 2025-11-20T21:56:45.876Z
Status : Awaiting Analysis
Published: 2025-11-20T21:16:06.617
Modified: 2025-11-21T15:15:53.110
Link: CVE-2025-63807
No data.