Record summary

CVE-2024-31396 has a selected CVSS score of 6.6 (medium).

Description

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List3.1.0 to < 3.1.12affected
3.0.0 to < 3.0.32affected
CVE Listprior to Ver.3.0.32affected
CVE Listprior to Ver.3.1.12affected

References

3