CVE-2025-31103

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*

History

13 May 2025, 15:15

Type Values Removed Values Added
First Time Appleple
Appleple a-blog Cms
References () https://developer.a-blogcms.jp/blog/news/security-update202503.html - () https://developer.a-blogcms.jp/blog/news/security-update202503.html - Vendor Advisory
References () https://jvn.jp/en/jp/JVN66982699/ - () https://jvn.jp/en/jp/JVN66982699/ - Third Party Advisory
References () https://developer.a-blogcms.jp/blog/news/entry-4197.html - () https://developer.a-blogcms.jp/blog/news/entry-4197.html - Vendor Advisory
CPE cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

31 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 05:15

Updated : 2025-05-13 15:15


NVD link : CVE-2025-31103

Mitre link : CVE-2025-31103


JSON object : View

Products Affected

appleple

  • a-blog_cms
CWE
CWE-502

Deserialization of Untrusted Data