Authentication Bypass Vulnerability in a-blog CMS by a-blog
CVE-2022-21142

9.8CRITICAL

Key Information:

Vendor
CVE Published:
24 February 2022

What is CVE-2022-21142?

A critical vulnerability exists in the a-blog CMS that allows remote, unauthenticated users to bypass authentication under certain conditions. This flaw threatens the integrity of the system, making it imperative for users to update to the latest versions to ensure security. Affected versions include those prior to 2.8.74 in the 2.8.x series, prior to 2.9.39 in the 2.9.x series, prior to 2.10.43 in the 2.10.x series, and prior to 2.11.41 in the 2.11.x series.

Affected Version(s)

a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.