Improper Authorization Vulnerability in fuyang_lipengjun Platform 1.0
CVE-2025-10675
Key Information:
- Vendor
Fuyang Lipengjun
- Status
- Vendor
- CVE Published:
- 18 September 2025
Badges
What is CVE-2025-10675?
A security vulnerability has been identified in version 1.0 of the fuyang_lipengjun platform. This flaw specifically affects the AttributeController function located in the /attribute/queryAll file. If exploited, it allows attackers to manipulate user permissions improperly, leading to unauthorized access and potential data breaches. The exploit code for this vulnerability has been made publicly available, making it essential for users of the platform to implement security measures to mitigate risks.
Affected Version(s)
platform 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved