An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated REST API Exposure Reveals Access Tokens in OneBlog 2.3.9

Wed, 29 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated REST API Exposure Reveals Access Tokens in OneBlog 2.3.9

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in OneBlog Rest API Components

Tue, 21 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in OneBlog Rest API Components

Thu, 16 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via Insecure REST API in OneBlog 2.3.9

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via Insecure REST API in OneBlog 2.3.9

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title OneBlog V2.3.9: Remote Information Disclosure via REST API

Sun, 12 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title OneBlog V2.3.9: Remote Information Disclosure via REST API

Sat, 11 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title OneBlog 2.3.9 Sensitive Information Disclosure via Misconfigured REST API

Fri, 10 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title OneBlog 2.3.9 Sensitive Information Disclosure via Misconfigured REST API

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in Oneblog V2.3.9 via REST API Components
Weaknesses CWE-200

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in Oneblog V2.3.9 via REST API Components
Weaknesses CWE-200

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Zhangyd-c
Zhangyd-c oneblog
Vendors & Products Zhangyd-c
Zhangyd-c oneblog

Tue, 07 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T14:17:11.579Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51937

cve-icon Vulnrichment

Updated: 2026-07-08T14:16:30.293Z

cve-icon NVD

Status : Deferred

Published: 2026-07-07T23:16:55.130

Modified: 2026-07-09T17:02:37.960

Link: CVE-2026-51937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:15:18Z

Weaknesses