CVE-2024-23180

HIGH

Appleple A-blog Cms < 2.9.0 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary code by uploading a specially crafted SVG file.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0220
EPSS Percentile 84.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
appleple/a-blog_cms < 2.9.0
Published Jan 23, 2024
Tracked Since Feb 18, 2026