CVE-2025-10086

MEDIUM

fuyang_lipengjun platform 1.0.0 - Incorrect Privilege Assignment in AdPositionController

Title source: llm
STIX 2.1

Description

A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. Affects another part than CVE-2025-9936.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.323042
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.323042
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.644661
Exploit, Third Party Advisory exploit
https://www.cnblogs.com/aibot/p/19063427

Scores

CVSS v3 6.3
EPSS 0.0030
EPSS Percentile 21.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
fuyang_lipengjun/platform 1.0.0
Published Sep 08, 2025
Tracked Since Feb 18, 2026