THREAT OPS › Threat News › [NVD] CVE-2025-13814 (HIGH 7.3) — A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit
[NVD] CVE-2025-13814 (HIGH 7.3) — A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit
CVE-2025-13814 CVSS: 7.3 HIGH Published: 2025-12-01T08:15:47.640
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Indicators of compromise
- CVE-2025-13814cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13814