Back

MEDIUM

zhangyd-c OneBlog RestApiController.java autoLink server-side request forgery

Published Mar 27, 2025

Description

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Mar 27, 2025
Updated Mar 27, 2025
Reserved Mar 26, 2025

CISA Vulnrichment

Updated Mar 27, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Mar 27, 2025
Updated Mar 27, 2025

GitHub

No data