CVE-2024-23348
CVE-2024-23348
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary JavaScript code by uploading a specially crafted SVG file.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
appleple inc. · a-blog cmsappleple inc. · a-blog cms Ver.2.10.x seriesappleple inc. · a-blog cms Ver.2.11.x seriesappleple inc. · a-blog cms Ver.3.0.x seriesappleple inc. · a-blog cms Ver.3.1.x seriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →