Metrics
Affected Vendors & Products
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moxi624
Moxi624 mogu Blog V2 |
|
| Vendors & Products |
Moxi624
Moxi624 mogu Blog V2 |
Mon, 20 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-20T15:27:00.317Z
Reserved: 2026-04-19T16:38:13.228Z
Link: CVE-2026-6625
No data.
Status : Received
Published: 2026-04-20T10:16:17.760
Modified: 2026-04-20T10:16:17.760
Link: CVE-2026-6625
No data.
OpenCVE Enrichment
Updated: 2026-04-20T14:57:53Z