Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14828 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. |
Wed, 23 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dogukanurker
Dogukanurker flaskblog |
|
| CPEs | cpe:2.3:a:dogukanurker:flaskblog:2.6.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Dogukanurker
Dogukanurker flaskblog |
Thu, 17 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-17T18:05:58.230Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28101
Updated: 2025-04-17T18:05:46.859Z
Status : Analyzed
Published: 2025-04-17T18:15:49.637
Modified: 2025-04-23T19:03:51.237
Link: CVE-2025-28101
No data.
OpenCVE Enrichment
No data.
EUVD