Описание
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.0 (включая) до 3.0.32 (исключая)Версия от 3.1.0 (включая) до 3.1.12 (исключая)
Одно из
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00751
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 6.6
github
больше 1 года назад
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.
EPSS
Процентиль: 73%
0.00751
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-94