Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T01:52:56.923Z
Reserved: 2024-04-03T08:01:33.449Z
Link: CVE-2024-31396
Updated: 2024-05-22T17:43:01.267Z
Status : Analyzed
Published: 2024-05-22T05:15:53.183
Modified: 2025-05-12T14:23:37.797
Link: CVE-2024-31396
No data.
OpenCVE Enrichment
No data.
Weaknesses