CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yandaozi:ppress:0.0.9:beta:*:*:*:*:*:*

History

25 Sep 2025, 19:34

Type Values Removed Values Added
References () https://github.com/quarter77/PPress-CMS_vulnerability_chain_details/blob/main/CVE-2025-54761%20Details.md - () https://github.com/quarter77/PPress-CMS_vulnerability_chain_details/blob/main/CVE-2025-54761%20Details.md - Exploit, Third Party Advisory
References () https://github.com/yandaozi/PPress/releases/tag/v0.0.9-beta - () https://github.com/yandaozi/PPress/releases/tag/v0.0.9-beta - Release Notes
CPE cpe:2.3:a:yandaozi:ppress:0.0.9:beta:*:*:*:*:*:*
First Time Yandaozi ppress
Yandaozi

19 Sep 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-287
CWE-269
CWE-384

19 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-19 20:15

Updated : 2025-09-25 19:34


NVD link : CVE-2025-54761

Mitre link : CVE-2025-54761

CVE.ORG link : CVE-2025-54761


JSON object : View

Products Affected

yandaozi

  • ppress
CWE
CWE-269

Improper Privilege Management

CWE-287

Improper Authentication

CWE-384

Session Fixation