CVE-2025-2835 | zhangyd-c OneBlog up to 2.3.9 RestApiController.java autoLink server-side request forgery (Issue 36)
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-2835. The attack can be launched remotely. Furthermore, there is an exploit available.