← CVE Tracker
7.3HIGH

CVE-2025-13814 — A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2.

Mogublog Project · Mogublog · Published 1 Dec 2025 · Modified 26 Sept 2026

Description

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

References

What to do
  1. Check whether Mogublog is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-13814