CVE-2025-63807
CRITICALUniversity-BBS <9e06bab430bfc729f27b4284ba7570db3b11ce84 - Auth Bypass
Title source: llmDescription
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://gist.github.com/Rycarl-Furry/3e93c6f0d48a29518adf341e0fc7e2dd
Scores
CVSS v3
9.8
EPSS
0.0043
EPSS Percentile
34.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1390
CWE-307
Status
published
Products (1)
2dogz/blogin
< 2024-11-09
Published
Nov 20, 2025
Tracked Since
Feb 18, 2026