CVE-2024-30420

MEDIUM

a-blog cms 3.0.0-3.0.31 and 3.1.0-3.1.11 - Authenticated Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may obtain arbitrary files on the server and information on the internal server that is not disclosed to the public.

References (2)

Core 2

Scores

CVSS v3 4.4
EPSS 0.0032
EPSS Percentile 23.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (1)
appleple/a-blog_cms 3.0.0 - 3.0.32
Published May 22, 2024
Tracked Since Feb 18, 2026