Arbitrary Script Execution Vulnerability in a-blog CMS by a-blog Inc.
CVE-2019-6034

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 December 2019

What is CVE-2019-6034?

The a-blog CMS before version 2.10.23, specifically versions 2.9.26 and 2.8.64, are susceptible to an arbitrary script execution vulnerability. This issue allows attackers to inject and execute malicious scripts within the application context due to improper validation of user inputs or other unspecified vectors. Such exploits can compromise the integrity and security of the application, potentially leading to unauthorized access and data breaches.

Affected Version(s)

a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.