Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
History

Tue, 30 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Appleple
Appleple a-blog Cms
CPEs cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
Vendors & Products Appleple
Appleple a-blog Cms

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 08:30:00 +0000

Type Values Removed Values Added
Description Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-05-19T08:09:26.427Z

Updated: 2025-05-19T14:42:50.286Z

Reserved: 2025-05-12T23:37:57.129Z

Link: CVE-2025-27566

cve-icon Vulnrichment

Updated: 2025-05-19T14:42:44.479Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-19T09:15:24.627

Modified: 2025-09-30T19:22:01.057

Link: CVE-2025-27566

cve-icon Redhat

No data.