CVE-2025-8546
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf. It is recommended to apply a patch to fix this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.45%
- CWE
- CWE-804, CWE-287
- Published
- 2025-08-05
- Last modified
- 2026-03-12
Affected products
- atjiu pybbs
Weakness type
Related vulnerabilities
- CVE-2024-23566 — HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha...
- CVE-2024-23567 — HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows...
- CVE-2026-13082 — GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
- CVE-2026-49953 — Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
- CVE-2026-40935 — WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-27411 — WordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerability
- CVE-2025-10423 — newbee-mall kaptcha mallKaptcha Captcha
- CVE-2025-40916 — Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha text