CVE-2026-30689

MEDIUM

blog.admin <= 8.0 - Sensitive Data Exposure via getinfobytoken API

Title source: llm
STIX 2.1

Description

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-284 CWE-863
Status published
Products (2)
anjoy8/blog.admin 8.0
anjoy8/Blog.Core < bcb4d17ccc71e206a0c2ff663faf4b399e19f687
Published Mar 27, 2026
Tracked Since Mar 29, 2026