Relative Path Traversal Vulnerability in a-blog CMS by a-blog
CVE-2024-23182

8.1HIGH

What is CVE-2024-23182?

A relative path traversal vulnerability exists in multiple versions of a-blog CMS, allowing an authenticated remote attacker to manipulate file paths. This flaw enables unauthorized deletion of arbitrary files on the server, potentially leading to significant data loss and service disruption. Versions affected include series 3.1.x prior to 3.1.7, 3.0.x prior to 3.0.29, 2.11.x prior to 2.11.58, 2.10.x prior to 2.10.50, and 2.9.0 and earlier. Keeping a-blog CMS updated to the latest version is crucial to mitigate risks associated with this vulnerability.

Affected Version(s)

a-blog cms Ver.2.9.0 and earlier

a-blog cms Ver.2.10.x series prior to Ver.2.10.50

a-blog cms Ver.2.11.x series prior to Ver.2.11.58

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.