Server-Side Request Forgery Vulnerability in a-blog CMS by a-blog
CVE-2025-36560
9.2CRITICAL
What is CVE-2025-36560?
A server-side request forgery vulnerability has been identified in multiple versions of a-blog CMS. This flaw allows an unauthenticated remote attacker to send maliciously crafted requests, potentially leading to the unauthorized exposure of sensitive information. Organizations using affected versions should implement immediate security measures to mitigate potential risks.
Affected Version(s)
a-blog cms Ver. 2.8.85 and earlier (Ver. 2.8.x series)
a-blog cms Ver. 3.1.43 and earlier (Ver. 3.1.x series)
a-blog cms Ver. 3.0.47 and earlier (Ver. 3.0.x series)
