Critical severity9.9OSV Advisory· Published Jan 26, 2026· Updated Jun 17, 2026
CVE-2025-70982
CVE-2025-70982
Description
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
44.1.0, v3.0.0, v3.0.1, …+ 1 more
- (no CPE)range: 4.1.0, v3.0.0, v3.0.1, …
- (no CPE)range: =4.5.0
- cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:*
- Range: =4.5.0
Patches
Vulnerability mechanics
References
2- github.com/chillzhuang/SpringBlade/issues/34nvdExploitIssue Tracking
- gist.github.com/old6ma/ea60151aa40ddc1cfb51fbaa0c173117nvdThird Party Advisory
News mentions
0No linked articles in our index yet.