CVE-2025-57805

CVSS

No CVSS.

T

he Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2.

Configurations

No configuration.

History

26 Aug 2025, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-25 22:15

Updated : 2025-08-26 13:41


NVD link : CVE-2025-57805

Mitre link : CVE-2025-57805

CVE.ORG link : CVE-2025-57805


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation