CVE-2024-23348: Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29,...

8.8 CVSS

Description

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary JavaScript code by uploading a specially crafted SVG file.

Classification

CVE ID: CVE-2024-23348

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types

Improper input validation

Affected Products

Vendor: appleple inc.

Product: a-blog cms Ver.3.1.x series, a-blog cms Ver.3.0.x series, a-blog cms Ver.2.11.x series, a-blog cms Ver.2.10.x series, a-blog cms

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.35% (probability of being exploited)

EPSS Percentile: 56.61% (scored less or equal to compared to others)

EPSS Date: 2025-06-07 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-23348
https://developer.a-blogcms.jp/blog/news/JVN-34565930.html
https://jvn.jp/en/jp/JVN34565930/

Timeline