CVE-2025-7897: Missing Authentication in harry0703 MoneyPrinterTurbo
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely.
CVE-2025-7897: Missing Authentication in harry0703 MoneyPrinterTurbo
Description
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-19T11:20:22.912Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687d085ca83201eaac02fc4f
Added to database: 7/20/2025, 3:16:44 PM
Last updated: 7/20/2025, 3:16:44 PM
Views: 1
Related Threats
CVE-2025-7896: Path Traversal in harry0703 MoneyPrinterTurbo
MediumCVE-2025-46385: CWE-918 Server-Side Request Forgery (SSRF) in Emby Windows
HighCVE-2025-46384: CWE-434 Unrestricted Upload of File with Dangerous Type in Emby Windows
HighCVE-2025-7895: Unrestricted Upload in harry0703 MoneyPrinterTurbo
MediumCVE-2025-46383: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Emby Windows
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.