Untrusted Data Deserialization in a-blog CMS by a-blog
CVE-2025-31103
7.5HIGH
What is CVE-2025-31103?
An untrusted data deserialization vulnerability exists in a-blog CMS that allows adversaries to craft specific requests, potentially leading to the storage of arbitrary files on the server where the CMS operates. This vulnerability exposes systems to threats where malicious scripts could be executed, compromising the integrity and security of the server.
Affected Version(s)
a-blog cms (Ver. 2.8.x series) prior to Ver.2.8.80
a-blog cms (Ver.2.10.x series) prior to Ver.2.10.58
a-blog cms (Ver.2.11.x series) prior to Ver.2.11.70
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
