← Back

CVE-2025-36560

nvd nist
Published: May 19, 2025Modified: Sep 30, 2025

JSON object

Loading...
9.2
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: vultures@jpcert.or.jp (Secondary)

Description

Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.

Affected (6)

Products: Appleple: A Blog Cms
1 product
A Blog Cms
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Appleple
From 2.10.0 to 2.10.63
From 2.11.0 to 2.11.75
From 2.8.0 to 2.8.85
From 2.9.0 to 2.9.52
From 3.0.0 to 3.0.47
From 3.1.0 to 3.1.43

References (2)

Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Third Party Advisory

Timeline

No history available yet.