Input Validation Vulnerability in a-blog CMS Affecting Multiple Versions
CVE-2024-23348

8.8HIGH

What is CVE-2024-23348?

This vulnerability arises from improper input validation within the a-blog CMS product, which impacts several versions across different series. Attackers with authenticated access can exploit this flaw by uploading specially crafted SVG files, leading to the execution of arbitrary JavaScript code. Such capability poses significant security risks, enabling a range of malicious activities that could compromise the integrity and security of affected web applications.

Affected Version(s)

a-blog cms Ver.2.9.0 and earlier

a-blog cms Ver.2.10.x series prior to Ver.2.10.50

a-blog cms Ver.2.11.x series prior to Ver.2.11.58

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.