PT-2024-23347 · Unknown · A-Blog Cms

Published

2024-05-22

·

Updated

2025-05-12

·

CVE-2024-30420

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions a-blog cms versions 3.0.x through 3.0.31 a-blog cms versions 3.1.x through 3.1.11
Description A server-side request forgery (SSRF) issue exists, allowing a user with administrator or higher privilege who can log in to the product to obtain arbitrary files on the server and information on the internal server that is not disclosed to the public.
Recommendations For versions 3.0.x through 3.0.31, update to version 3.0.32 or later. For versions 3.1.x through 3.1.11, update to version 3.1.12 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-30420

Affected Products

A-Blog Cms