CVE-2025-31103
HIGH EXPLOITEDAppleple A-blog Cms < 2.8.80 - Insecure Deserialization
Title source: ruleDescription
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Scores
CVSS v3
7.5
EPSS
0.0043
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation Intel
VulnCheck KEV
2025-03-28
Classification
CWE
CWE-502
Status
published
Affected Products (1)
appleple/a-blog_cms
< 2.8.80
Timeline
Published
Mar 31, 2025
Tracked Since
Feb 18, 2026