CVE Details
Basic Information
| Title |
CVE-2025-27566 |
| Type |
cve |
| Published |
2025-05-19T09:15:24 |
| Last Seen |
2025-05-19T09:22:35 |
CVSS Information
| Base Score |
3.8 (LOW) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
HIGH |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
LOW |
| Integrity Impact |
LOW |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
A path traversal vulnerability in a-blog CMS versions before 3.1.43 and 3.0.47 allows unauthorized file access via insufficient path validation in the backup feature. Exploitation requires administrator privileges. |
| AI Severity |
Medium |
| Vendor |
a-blog CMS Community |
| Product |
a-blog CMS |
| Affected Version |
3.1.43, 3.0.47 |
Additional Information
| CVE List |
CVE-2025-27566 |
| CWE List |
CWE-22 |
| Bulletin Family |
cve |
Description
Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If…
CVSS Score Summary
Base Score: %!f(string=#) (LOW)
View Full CVE Details