CVE-2025-70833

Source
https://cve.org/CVERecord?id=CVE-2025-70833
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70833.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-70833
Published
2026-02-20T00:00:00Z
Modified
2026-08-30T03:45:37Z
Severity
  • 9.4 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70833.json"
}
References

Affected packages

Git / github.com/lkw199711/smanga

Affected ranges

Type
GIT
Repo
https://github.com/lkw199711/smanga
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:lkw199711:smanga:3.2.7:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.2.7"
        },
        {
            "last_affected": "3.2.7"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.2.7
v3.*
v3.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70833.json"