CVE-2025-28101

MEDIUM

flaskBlog 2.6.1 - Arbitrary File Deletion via Post Title Parameter

Title source: llm
STIX 2.1

Description

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
dogukanurker/flaskblog 2.6.1
Published Apr 17, 2025
Tracked Since Feb 18, 2026