CVE-2024-31396

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
22/05/2024
Last modified:
12/05/2025

Description

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.32 (excluding)
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.12 (excluding)