CVE-2025-15151
A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.31%
- CWE
- CWE-260, CWE-255
- Published
- 2025-12-28
- Last modified
- 2026-03-12
Affected products
- TaleLin Lin-CMS
- TaleLin Lin-CMS
- TaleLin Lin-CMS
- TaleLin Lin-CMS
- TaleLin Lin-CMS
- TaleLin Lin-CMS
Weakness type
Related vulnerabilities
- CVE-2019-25465 — Hisilicon HiIpcam V100R003 Information Disclosure via Directory Traversal
- CVE-2023-53770 — MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint
- CVE-2023-53739 — Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure
- CVE-2025-33119 — IBM QRadar SIEM Information Disclosure
- CVE-2025-36002 — IBM Sterling B2B Integrator information disclosure
- CVE-2025-36100 — IBM MQ information disclosure
- CVE-2025-57754 — eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)
- CVE-2025-6513 — BRAIN2 Configuration file for database access not sufficiently secured