CVE-2024-27279
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
12/03/2024
Last modified:
13/05/2025
Description
Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | 2.10.51 (including) | |
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | 2.11.0 (including) | 2.11.59 (including) |
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.0.30 (including) |
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | 3.1.0 (including) | 3.1.9 (including) |
To consult the complete list of CPE names with products and versions, see this page