CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-23182: Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29,...

8.1 CVSS

Description

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to delete arbitrary files on the server.

Classification

CVE ID: CVE-2024-23182

CVSS Base Severity: HIGH

CVSS Base Score: 8.1

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem Types

Relative path traversal

Affected Products

Vendor: appleple inc.

Product: a-blog cms Ver.3.1.x series, a-blog cms Ver.3.0.x series, a-blog cms Ver.2.11.x series, a-blog cms Ver.2.10.x series, a-blog cms

Exploit Prediction Scoring System (EPSS)

EPSS Score: 2.0% (probability of being exploited)

EPSS Percentile: 82.79% (scored less or equal to compared to others)

EPSS Date: 2025-06-23 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-23182
https://developer.a-blogcms.jp/blog/news/JVN-34565930.html
https://jvn.jp/en/jp/JVN34565930/

Timeline