CVE-2024-23182

HIGH

a-blog cms < 2.9.0 - Authenticated Path Traversal and Arbitrary File Deletion

Title source: llm
STIX 2.1

Description

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to delete arbitrary files on the server.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0075
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
appleple/a-blog_cms < 2.9.0
Published Jan 23, 2024
Tracked Since Feb 18, 2026