CVE-2024-27279

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*

History

13 May 2025, 15:13

Type Values Removed Values Added
CPE cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
References () https://developer.a-blogcms.jp/blog/news/JVN-48443978.html - () https://developer.a-blogcms.jp/blog/news/JVN-48443978.html - Vendor Advisory
References () https://jvn.jp/en/jp/JVN48443978/ - () https://jvn.jp/en/jp/JVN48443978/ - Third Party Advisory
First Time Appleple
Appleple a-blog Cms

12 Mar 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 09:15

Updated : 2025-05-13 15:13


NVD link : CVE-2024-27279

Mitre link : CVE-2024-27279


JSON object : View

Products Affected

appleple

  • a-blog_cms
CWE

No CWE.