Impact
The affected a-blog CMS versions unlock an unsafe path traversal logic that lets anyone construct URLs containing directory traversal sequences. The flaw allows reading any file reachable from the web root and deleting by exposing arbitrary files and integrity by enabling arbitrary file removal, potentially destroying content or altering application configuration. The underlying weakness is a classic path traversal (CWE-22).
Affected Systems
Appleple inc. product a-blog CMS, versions 3.2.33 and earlier.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating a moderate risk level, and no EPSS score is available. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is an unauthenticated HTTP request to a CMS path that includes directory traversal sequences, which can be automated. Because the flaw can be triggered without user interaction, it is likely to be exploited by automated scripts that scan for vulnerable installations on the public Internet.
OpenCVE Enrichment