A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Nov 2025 05:45:00 +0900

Type Values Removed Values Added
First Time appeared Pybbs Project
Pybbs Project pybbs
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:pybbs_project:pybbs:*:*:*:*:*:*:*:*
Vendors & Products Pybbs Project
Pybbs Project pybbs

Tue, 28 Oct 2025 07:30:00 +0900

Type Values Removed Values Added
First Time appeared Atjiu
Atjiu pybbs
Vendors & Products Atjiu
Atjiu pybbs

Tue, 28 Oct 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Oct 2025 01:45:00 +0900

Type Values Removed Values Added
Description A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
Title atjiu pybbs UserApiController.java information disclosure
Weaknesses CWE-200
CWE-284
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-27T17:26:20.100Z

Reserved: 2025-10-26T16:51:50.650Z

Link: CVE-2025-12297

cve-icon Vulnrichment

Updated: 2025-10-27T17:25:49.872Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T17:15:37.300

Modified: 2025-11-05T20:38:11.980

Link: CVE-2025-12297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-28T07:03:39Z