Untrusted Data Deserialization in a-blog CMS by a-blog
CVE-2025-31103

7.5HIGH

What is CVE-2025-31103?

An untrusted data deserialization vulnerability exists in a-blog CMS that allows adversaries to craft specific requests, potentially leading to the storage of arbitrary files on the server where the CMS operates. This vulnerability exposes systems to threats where malicious scripts could be executed, compromising the integrity and security of the server.

Affected Version(s)

a-blog cms (Ver. 2.8.x series) prior to Ver.2.8.80

a-blog cms (Ver.2.10.x series) prior to Ver.2.10.58

a-blog cms (Ver.2.11.x series) prior to Ver.2.11.70

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.