CVE-2024-23180: Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29,...

Description

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary code by uploading a specially crafted SVG file.

Classification

CVE ID: CVE-2024-23180

Problem Types

Improper input validation

Affected Products

Vendor: appleple inc.

Product: a-blog cms Ver.3.1.x series, a-blog cms Ver.3.0.x series, a-blog cms Ver.2.11.x series, a-blog cms Ver.2.10.x series, a-blog cms

Exploit Prediction Scoring System (EPSS)

EPSS Score: 1.63% (probability of being exploited)

EPSS Percentile: 81.0% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-23180
https://developer.a-blogcms.jp/blog/news/JVN-34565930.html
https://jvn.jp/en/jp/JVN34565930/

Timeline