Path Traversal Vulnerability in a-blog CMS by a-blog
CVE-2025-27566

5.1MEDIUM

Key Information:

Vendor
CVE Published:
19 May 2025

What is CVE-2025-27566?

A path traversal vulnerability has been identified in a-blog CMS, affecting versions prior to 3.1.43 and 3.0.47. This issue stems from inadequate path validation within the backup feature, allowing an authenticated remote attacker with administrator privileges to navigate through the file system. Exploiting this vulnerability could enable unauthorized access to sensitive files or deletion of files on the server, posing a significant risk to data integrity and server security.

Affected Version(s)

a-blog cms prior to Ver. 3.1.43 (Ver. 3.1.x series)

a-blog cms prior to Ver. 3.0.47 (Ver. 3.0.x series)

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.