๐Ÿ” CVE Alert

CVE-2026-30689

MEDIUM 4.3
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.

CWE CWE-863
Vendor anjoy8
Product blog.core
Published Mar 27, 2026
Last Updated Jul 5, 2026
Stay Ahead of the Next One

Get instant alerts for anjoy8 blog.core

Be the first to know when new medium vulnerabilities affecting anjoy8 blog.core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

anjoy8 / Blog.Core
0 โ‰ค bcb4d17ccc71e206a0c2ff663faf4b399e19f687

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40 github.com: https://github.com/anjoy8/Blog.Core/blob/bcb4d17ccc71e206a0c2ff663faf4b399e19f687/Blog.Core.Api/Controllers/UserController.cs#L139-L140