Path Traversal Vulnerability in a-blog CMS by a-blog
CVE-2025-27566
5.1MEDIUM
What is CVE-2025-27566?
A path traversal vulnerability has been identified in a-blog CMS, affecting versions prior to 3.1.43 and 3.0.47. This issue stems from inadequate path validation within the backup feature, allowing an authenticated remote attacker with administrator privileges to navigate through the file system. Exploiting this vulnerability could enable unauthorized access to sensitive files or deletion of files on the server, posing a significant risk to data integrity and server security.
Affected Version(s)
a-blog cms prior to Ver. 3.1.43 (Ver. 3.1.x series)
a-blog cms prior to Ver. 3.0.47 (Ver. 3.0.x series)
