Session Hijacking Vulnerability in a-blog CMS by a-blog
CVE-2025-41429

2.1LOW

Key Information:

Vendor
CVE Published:
19 May 2025

What is CVE-2025-41429?

The a-blog CMS suffers from a vulnerability where logs are improperly neutralized across multiple versions. This flaw can be exploited in conjunction with another identified vulnerability, allowing a remote, unauthenticated attacker to hijack an active session of a legitimate user. This vulnerability highlights the importance of proper log management and system security to mitigate unauthorized access risks.

Affected Version(s)

a-blog cms Ver. 2.8.85 and earlier (Ver. 2.8.x series)

a-blog cms Ver. 3.1.43 and earlier (Ver. 3.1.x series)

a-blog cms Ver. 3.0.47 and earlier (Ver. 3.0.x series)

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.