Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w57q-v7qr-v5m7

Опубликовано: 19 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 3.8

Описание

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

EPSS

Процентиль: 34%
0.00135
Низкий

5.1 Medium

CVSS4

3.8 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.8
nvd
9 месяцев назад

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

EPSS

Процентиль: 34%
0.00135
Низкий

5.1 Medium

CVSS4

3.8 Low

CVSS3

Дефекты

CWE-22