CVE Database
/

CVE-2025-31103

Back to search

CVE-2025-31103

Published: Mar 31, 2025

Modified: Mar 31, 2025

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.

VendorProductVersions

appleple inc.

a-blog cms (Ver.3.1.x series)

affected
prior to Ver.3.1.37

appleple inc.

a-blog cms (Ver.3.0.x series)

affected
prior to Ver.3.0.41

appleple inc.

a-blog cms (Ver.2.11.x series)

affected
prior to Ver.2.11.70

appleple inc.

a-blog cms (Ver.2.10.x series)

affected
prior to Ver.2.10.58

appleple inc.

a-blog cms (Ver.2.9.x series)

affected
prior to Ver.2.9.46

appleple inc.

a-blog cms (Ver. 2.8.x series)

affected
prior to Ver.2.8.80

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now