← Back

CVE-2025-41429

nvd nist
Published: May 19, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.1
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: vultures@jpcert.or.jp (Secondary)

Description

a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.

Affected (6)

Products: Appleple: A Blog Cms
1 product
A Blog Cms
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Appleple
From 2.10.0 to 2.10.63
From 2.11.0 to 2.11.75
From 2.8.0 to 2.8.85
From 2.9.0 to 2.9.52
From 3.0.0 to 3.0.47
From 3.1.0 to 3.1.43

References (2)

Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Third Party Advisory

Timeline

No history available yet.