developer.a-blogcms.jp
https://developer.a-blogcms.jp/blog/news/entry-4197.html CVE-2025-31103
HIGH
A-blog CMS Untrusted Data Deserialization
Record summary
CVE-2025-31103 has a selected CVSS score of 7.5 (high).
Description
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 31, 2025 · Source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
a-blog cmsBrowse Appleple Inc. / a-blog cms | VulnCheck | Version data not supplied | |
a-blog cms (Ver. 2.8.x series)Browse appleple inc. / a-blog cms (Ver. 2.8.x series) | CVE List | prior to Ver.2.8.80 | affected |
a-blog cms (Ver.2.10.x series)Browse appleple inc. / a-blog cms (Ver.2.10.x series) | CVE List | prior to Ver.2.10.58 | affected |
a-blog cms (Ver.2.11.x series)Browse appleple inc. / a-blog cms (Ver.2.11.x series) | CVE List | prior to Ver.2.11.70 | affected |
a-blog cms (Ver.2.9.x series)Browse appleple inc. / a-blog cms (Ver.2.9.x series) | CVE List | prior to Ver.2.9.46 | affected |
a-blog cms (Ver.3.0.x series)Browse appleple inc. / a-blog cms (Ver.3.0.x series) | CVE List | prior to Ver.3.0.41 | affected |
a-blog cms (Ver.3.1.x series)Browse appleple inc. / a-blog cms (Ver.3.1.x series) | CVE List | prior to Ver.3.1.37 | affected |
References
4developer.a-blogcms.jp
https://developer.a-blogcms.jp/blog/news/security-update202503.html jvn.jp
https://jvn.jp/en/jp/JVN66982699 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-31103