CVE-2025-70833
critical · 9.4An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.
9.4
CVSS
0.4%
EPSS (exploit prob.)
35th
EPSS percentile
2026-02-20
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weaknesses
CWE-287CWE-639
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| lkw199711 | smanga | 3.2.7 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-70833