Vulnerability Description
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anjoy8 | Blog.Admin | 8.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40ExploitThird Party Advisory
- https://github.com/anjoy8/Blog.Core/blob/bcb4d17ccc71e206a0c2ff663faf4b399e19f68
FAQ
What is CVE-2026-30689?
CVE-2026-30689 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account i...
How severe is CVE-2026-30689?
CVE-2026-30689 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30689?
Check the references section above for vendor advisories and patch information. Affected products include: Anjoy8 Blog.Admin.