Medium severity6.5NVD Advisory· Published Oct 30, 2025· Updated Jun 17, 2026
CVE-2025-60319
CVE-2025-60319
Description
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*
- (no CPE)range: v4.0.11
- PerfreeBlog/PerfreeBlogdescription
Patches
Vulnerability mechanics
References
2- github.com/PerfreeBlog/PerfreeBlog/commit/103c79165e3a41a1729188fdc8a1e90c97c0a06dnvdPatch
- github.com/PerfreeBlog/PerfreeBlog/issues/20nvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.