← Back

CVE-2025-31103

nvd nist
Published: Mar 31, 2025Modified: May 13, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.

Affected (6)

Products: Appleple: A Blog Cms
1 product
A Blog Cms
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Appleple
Up to 2.8.80
From 2.10.0 to 2.10.58
From 2.11.0 to 2.11.70
From 2.9.0 to 2.9.46
From 3.0.0 to 3.0.41
From 3.1.0 to 3.1.37

References (3)

Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Third Party Advisory

Timeline

No history available yet.