← Back

CVE-2025-70833

nvd nist
Published: Feb 20, 2026Modified: Feb 26, 2026

JSON object

Loading...
9.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Exploitability: 3.9 / Impact: 5.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

Affected (1)

Products: Lkw199711: Smanga
1 product
Smanga
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.2.7

References (1)

Source: cve@mitre.org
Broken Link

Timeline

No history available yet.