CVE-2025-57805

The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-08-25 22:15

Updated : 2025-08-26 13:41


NVD link : CVE-2025-57805

Mitre link : CVE-2025-57805

CVE.ORG link : CVE-2025-57805


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation