Vulnerabilities
Vulnerable Software
Appleple:  >> A-Blog Cms  >> 3.0.36  Security Vulnerabilities
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
CVSS Score
4.8
EPSS Score
0.002
Published
2025-05-19
Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
CVSS Score
3.8
EPSS Score
0.005
Published
2025-05-19
Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
CVSS Score
5.4
EPSS Score
0.001
Published
2025-05-19
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.
CVSS Score
8.6
EPSS Score
0.003
Published
2025-05-19
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
CVSS Score
7.5
EPSS Score
0.004
Published
2025-03-31


Contact Us

Shodan ® - All rights reserved