CVE-2025-8549 Details
Description
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. The manipulation leads to weak password requirements. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as d09cb19a8e7d7e5151282926ada54080244d499f. It is recommended to apply a patch to fix this issue.
A critical vulnerability exists in Atjiu Pybbs versions up to 6.0.0, specifically in the UserAdminController.java file. The issue arises in the 'update' function, where password requirements are insufficiently enforced. This flaw allows users to create accounts with weak passwords, potentially consisting of a single digit. Such lax requirements can lead to account compromises through password guessing or brute-force attacks. The vulnerability can be exploited remotely, and while the exploitation is considered difficult, a public exploit is available.
Users are advised to update to the latest version of Atjiu Pybbs, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/atjiu/pybbs/issues/201 | CISA-ADP | ExploitIssue Tracking |
| https://github.com/atjiu/pybbs/issues/201#issue-3256288016 | CISA-ADP | ExploitIssue Tracking |
| https://github.com/atjiu/pybbs/issues/201#issuecomment-3134733216 | CISA-ADP | Issue Tracking |
| https://github.com/atjiu/pybbs/commit/d09cb19a8e7d7e5151282926ada54080244d499f | [email protected] | Patch |
| https://github.com/atjiu/pybbs/issues/201 | [email protected] | ExploitIssue Tracking |
| https://github.com/atjiu/pybbs/issues/201#issue-3256288016 | [email protected] | ExploitIssue Tracking |
| https://github.com/atjiu/pybbs/issues/201#issuecomment-3134733216 | [email protected] | Issue Tracking |
| https://vuldb.com/?ctiid.318678 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.318678 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.622187 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pybbs project pybbs | <= 6.0.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| Aug 5, 2025 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | New CVE Received | [email protected] |