Vulnerability Description
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appleple | A-Blog Cms | >= 2.8.0, <= 2.8.85 |
Related Weaknesses (CWE)
References
- https://developer.a-blogcms.jp/blog/news/JVNVU-90760614.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU90760614/Third Party Advisory
FAQ
What is CVE-2025-36560?
CVE-2025-36560 is a vulnerability with a CVSS score of 8.6 (HIGH). Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by send...
How severe is CVE-2025-36560?
CVE-2025-36560 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36560?
Check the references section above for vendor advisories and patch information. Affected products include: Appleple A-Blog Cms.