{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2021-07-02"
              }
            ]
          }
        ]
      }
    }
  ],
  "details": "An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an attacker can directly access the admin dashboard without valid credentials. This allows full administrative control including viewing/modifying user accounts, managing orders, changing payments, and editing product listings. Successful exploitation can lead to information disclosure, data manipulation, and privilege escalation.",
  "id": "CVE-2025-65276",
  "modified": "2026-03-13T21:47:03.810097370Z",
  "published": "2025-11-26T20:15:49.660Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://gist.github.com/whoisrushi/c3bfcd1adf96d80952edbd03d0310836"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}