CVE-2025-9461

MEDIUM

diyhi bbs < 6.8 - Exposure of Sensitive Information via File Compression Handler

Title source: llm
STIX 2.1

Description

A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes information disclosure. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.321296
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.321296
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.634295

Scores

CVSS v3 4.3
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (1)
diyhi/bbs < 6.8
Published Aug 26, 2025
Tracked Since Feb 18, 2026