CVE-2025-31103
31.03.2025, 05:15
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.Enginsight
Vendor | Product | Version |
---|---|---|
appleple | a-blog_cms | 𝑥 ≤ 2.8.80 |
appleple | a-blog_cms | 2.9.0 ≤ 𝑥 ≤ 2.9.46 |
appleple | a-blog_cms | 2.10.0 ≤ 𝑥 < 2.10.58 |
appleple | a-blog_cms | 2.11.0 ≤ 𝑥 < 2.11.70 |
appleple | a-blog_cms | 3.0.0 ≤ 𝑥 < 3.0.41 |
appleple | a-blog_cms | 3.1.0 ≤ 𝑥 < 3.1.37 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration