Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
History

Tue, 13 May 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Appleple
Appleple a-blog Cms
CPEs cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
Vendors & Products Appleple
Appleple a-blog Cms
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Mon, 31 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 05:00:00 +0000

Type Values Removed Values Added
Description Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Weaknesses CWE-502
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-03-31T04:54:03.868Z

Updated: 2025-03-31T12:59:20.794Z

Reserved: 2025-03-26T09:54:15.256Z

Link: CVE-2025-31103

cve-icon Vulnrichment

Updated: 2025-03-31T12:59:15.358Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-31T05:15:16.500

Modified: 2025-05-13T15:15:19.237

Link: CVE-2025-31103

cve-icon Redhat

No data.