a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 19 May 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session. | |
Weaknesses | CWE-117 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: jpcert
Published: 2025-05-19T08:07:38.068Z
Updated: 2025-05-19T15:46:29.408Z
Reserved: 2025-05-12T23:37:54.373Z
Link: CVE-2025-41429

Updated: 2025-05-19T15:46:23.850Z

Status : Awaiting Analysis
Published: 2025-05-19T09:15:25.160
Modified: 2025-05-19T13:35:20.460
Link: CVE-2025-41429

No data.