CVE-2025-32999
Published: May 19, 2025
Modified: May 19, 2025
CVSS v3.1
5.4
Description
Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
| Vendor | Product | Versions |
|---|---|---|
appleple inc. | a-blog cms | affected prior to Ver. 3.1.43 (Ver. 3.1.x series) |
appleple inc. | a-blog cms | affected prior to Ver. 3.0.47 (Ver. 3.0.x series) |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now