← All CVEs

CVE-2025-70833

critical · 9.4

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

9.4
CVSS
0.4%
EPSS (exploit prob.)
35th
EPSS percentile
2026-02-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses

CWE-287CWE-639

Affected products

VendorProductAffected versions
lkw199711smanga3.2.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-70833