CVE-2025-9005
LOWMtons Mblog < 3.5.0 - Information Disclosure
Title source: ruleDescription
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Exploits (1)
Scores
CVSS v3
3.7
EPSS
0.0005
EPSS Percentile
14.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-209
CWE-200
Status
published
Products (1)
mtons/mblog
< 3.5.0
Published
Aug 15, 2025
Tracked Since
Feb 18, 2026