Junglewise Threat Intelligence

CVE-2025-13815: moxi159753 Mogu Blog unrestricted file upload

CVE-2025-13815 · Severity: medium · CVSS 6.3 · Published 2025-12-01

Technologies: Mogublog Project Mogublog, Moxi159753 Mogu Blog. Vendors: Mogublog Project, Moxi159753.

Executive brief

Mogu Blog is a blogging platform used to create and manage online content. An attacker can upload arbitrary files without authentication via the /file/pictures endpoint, potentially allowing them to store malicious code on the server or gain control of the application and underlying infrastructure.

Technical details

The vulnerability is an unrestricted file upload flaw in Mogu Blog v2 up to version 5.2, affecting an unauthenticated endpoint at /file/pictures. The vulnerability exists in the file upload handler which fails to properly validate or restrict the filedatas parameter, allowing an attacker to upload arbitrary files without authentication. An attacker can send a crafted HTTP request to upload malicious files such as web shells, potentially achieving remote code execution or defacement. The vendor was contacted early but did not respond, and public exploits are now available.

Affected products

  • moxi159753 Mogu Blog v2 up to 5.2

Timeline

  • 2025-12-01: disclosed
  • exploited: public exploit available

References

Related threats