CVE-2025-5512 | quequnlong shiyi-blog up to 1.2.1 Administrator Backend verifyPassword improper authentication
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2025-5512. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.