CVE-2025-55736
6.5MEDIUMflaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem
Published: 8/19/2025Updated: 8/22/2025
Description
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
AI AnalysisPowered by AI
Affected Products
dogukanurkerflaskblog
References
- https://github.com/DogukanUrker/FlaskBlog/security/advisories/GHSA-6q83-vfmq-wf72ExploitThird Party Advisory