Record summary

CVE-2025-31103 has a selected CVSS score of 7.5 (high).

Description

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 31, 2025 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE Listprior to Ver.2.8.80affected
CVE Listprior to Ver.2.10.58affected
CVE Listprior to Ver.2.11.70affected
CVE Listprior to Ver.2.9.46affected
CVE Listprior to Ver.3.0.41affected
CVE Listprior to Ver.3.1.37affected

References

4