Vulnerability Description
Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appleple | A-Blog Cms | >= 3.0.0, < 3.0.47 |
Related Weaknesses (CWE)
References
- https://developer.a-blogcms.jp/blog/news/JVNVU-90760614.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU90760614/Third Party Advisory
FAQ
What is CVE-2025-27566?
CVE-2025-27566 is a vulnerability with a CVSS score of 3.8 (LOW). Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploit...
How severe is CVE-2025-27566?
CVE-2025-27566 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27566?
Check the references section above for vendor advisories and patch information. Affected products include: Appleple A-Blog Cms.