Aller au contenu

Fiche vulnérabilité

CVE-2025-27566 : faille élevée appleple a-blog cms (CVSS 7.2)

Description

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 mai 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • appleple a-blog cms

Références

Rechercher une autre vulnérabilité dans la base CVE