Excessive Authentication Attempts Vulnerability in mtons mblog by mtons
CVE-2025-8927
Key Information:
Badges
What is CVE-2025-8927?
An issue was found in the mtons mblog software affecting versions up to 3.5.0. The vulnerability lies within the '/email/send_code' functionality of the Verification Code Handler. It allows remote attackers to exploit improper restrictions on authentication attempts, potentially leading to excessive attempts without proper control. Successful exploitation may require sophisticated techniques, making it a challenging threat. Awareness and mitigation strategies are critical for protecting against potential exploitation of this vulnerability.
Affected Version(s)
mblog 3.0
mblog 3.1
mblog 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved