Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2025-31103", "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "state": "PUBLISHED", "assignerShortName": "jpcert", "dateReserved": "2025-03-26T09:54:15.256Z", "datePublished": "2025-03-31T04:54:03.868Z", "dateUpdated": "2025-03-31T12:59:20.794Z"}, "containers": {"cna": {"affected": [{"vendor": "appleple inc.", "product": "a-blog cms (Ver.3.1.x series)", "versions": [{"version": "prior to Ver.3.1.37", "status": "affected"}]}, {"vendor": "appleple inc.", "product": "a-blog cms (Ver.3.0.x series)", "versions": [{"version": "prior to Ver.3.0.41", "status": "affected"}]}, {"vendor": "appleple inc.", "product": "a-blog cms (Ver.2.11.x series)", "versions": [{"version": "prior to Ver.2.11.70", "status": "affected"}]}, {"vendor": "appleple inc.", "product": "a-blog cms (Ver.2.10.x series)", "versions": [{"version": "prior to Ver.2.10.58", "status": "affected"}]}, {"vendor": "appleple inc.", "product": "a-blog cms (Ver.2.9.x series)", "versions": [{"version": "prior to Ver.2.9.46", "status": "affected"}]}, {"vendor": "appleple inc.", "product": "a-blog cms (Ver. 2.8.x series)", "versions": [{"version": "prior to Ver.2.8.80", "status": "affected"}]}], "descriptions": [{"lang": "en", "value": "Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server."}], "problemTypes": [{"descriptions": [{"description": "Deserialization of untrusted data", "lang": "en-US", "cweId": "CWE-502", "type": "CWE"}]}], "references": [{"url": "https://developer.a-blogcms.jp/blog/news/security-update202503.html"}, {"url": "https://developer.a-blogcms.jp/blog/news/entry-4197.html"}, {"url": "https://jvn.jp/en/jp/JVN66982699/"}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en-US", "value": "GENERAL"}], "cvssV3_0": {"version": "3.0", "baseSeverity": "HIGH", "baseScore": 7.5, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}}], "providerMetadata": {"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert", "dateUpdated": "2025-03-31T04:54:03.868Z"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2025-03-31T12:59:04.427491Z", "id": "CVE-2025-31103", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-03-31T12:59:20.794Z"}}]}}