CVE-2025-55736
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
Vendor
Product
CWE
Yayın Tarihi
2025-08-19 19:15:37
Güncelleme
2025-08-22 20:56:14
Source Identifier
security-advisories@github.com
KEV Date Added
-