CVE-2025-9005

LOW

Mtons Mblog < 3.5.0 - Information Disclosure

Title source: rule

Description

A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Exploits (1)

gitee 3,324 stars
by mtons · javawriteup
https://gitee.com/mtons/mblog/issues/ICPMJO

Scores

CVSS v3 3.7
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-209 CWE-200
Status published
Products (1)
mtons/mblog < 3.5.0
Published Aug 15, 2025
Tracked Since Feb 18, 2026