developer.a-blogcms.jp
https://developer.a-blogcms.jp/blog/news/JVN-70977403.html CVE-2024-31396
MEDIUM
Record summary
CVE-2024-31396 has a selected CVSS score of 6.6 (medium).
Description
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
a-blog_cmsBrowse appleple / a-blog_cmsDefault status: unknown | CVE List | 3.1.0 to < 3.1.12 | affected |
| 3.0.0 to < 3.0.32 | affected | ||
a-blog cms Ver.3.0.x seriesBrowse appleple inc. / a-blog cms Ver.3.0.x series | CVE List | prior to Ver.3.0.32 | affected |
a-blog cms Ver.3.1.x seriesBrowse appleple inc. / a-blog cms Ver.3.1.x series | CVE List | prior to Ver.3.1.12 | affected |
References
3jvn.jp
https://jvn.jp/en/jp/JVN70977403 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-31396