---
id: CVE-2025-13814
title: A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2
summary: >-
  A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2.
  Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file
  /file/uploadPicsByUrl. The manipulation results in server-side request
  forgery. The at…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: mogublog_project
product: mogublog
affected:
  - mogublog <= 5.2
published: '2025-12-01'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13814'
references:
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/mogu_blog_v2-ssrf-1/report.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/Xzzz111/exps/blob/main/archives/mogu_blog_v2-ssrf-1/report.md#proof-of-concept
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.333823'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333823'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.692105'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00527
epssPercentile: 0.42241
ingestedAt: '2026-09-03T03:55:23.389Z'
---

## Overview

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `mogublog <= 5.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
