Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 19 May 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: jpcert
Published: 2025-05-19T08:09:26.427Z
Updated: 2025-05-19T14:42:50.286Z
Reserved: 2025-05-12T23:37:57.129Z
Link: CVE-2025-27566

Updated: 2025-05-19T14:42:44.479Z

Status : Awaiting Analysis
Published: 2025-05-19T09:15:24.627
Modified: 2025-05-19T13:35:20.460
Link: CVE-2025-27566

No data.