Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
History

Mon, 31 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 05:00:00 +0000

Type Values Removed Values Added
Description Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Weaknesses CWE-502
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-03-31T12:59:20.794Z

Reserved: 2025-03-26T09:54:15.256Z

Link: CVE-2025-31103

cve-icon Vulnrichment

Updated: 2025-03-31T12:59:15.358Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-31T05:15:16.500

Modified: 2025-04-01T20:26:30.593

Link: CVE-2025-31103

cve-icon Redhat

No data.