- Description
- flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- flaskblog
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-425
- Hype score
- Not currently trending
CVE-2025-55736 flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, p… https://t.co/ZwSS3lydtA
@CVEnew
19 Aug 2025
250 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-55736: CRITICAL] FlaskBlog app vulnerability alert: Update to version 2.8.1 to fix a security flaw allowing users to elevate roles to "admin." Vulnerability found in routes/adminPanelUsers file.#cve,CVE-2025-55736,#cybersecurity https://t.co/XciK7o2Pmv https://t.co/28U0
@CveFindCom
19 Aug 2025
168 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5EEEDB77-8F07-4D42-A2BE-34013446D9F8",
"versionEndIncluding": "2.8.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]