appleple a-blog cms
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*
- <= 3.1.42
- <= 3.0.46
- <= 2.11
- <= 2.10
- <= 2.9
- <= 2.8
- <= 2.7
A path traversal vulnerability has been identified in a-blog cms versions prior to 3.1.43 and 3.0.47. This vulnerability arises from inadequate path validation in the backup feature, allowing remote authenticated attackers with administrator privileges to access or delete any file on the server.
Exploitation of this vulnerability could lead to unauthorized file access or deletion on the server.
Users are advised to update a-blog cms to the latest version. For versions 2.11 and earlier, which are no longer supported, no update is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.