Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Sep 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Appleple
Appleple a-blog Cms |
|
CPEs | cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Appleple
Appleple a-blog Cms |
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 19 May 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: jpcert
Published: 2025-05-19T08:09:26.427Z
Updated: 2025-05-19T14:42:50.286Z
Reserved: 2025-05-12T23:37:57.129Z
Link: CVE-2025-27566

Updated: 2025-05-19T14:42:44.479Z

Status : Analyzed
Published: 2025-05-19T09:15:24.627
Modified: 2025-09-30T19:22:01.057
Link: CVE-2025-27566

No data.