Vulnerability Description
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appleple | A-Blog Cms | >= 2.8.0, <= 2.8.85 |
Related Weaknesses (CWE)
References
- https://developer.a-blogcms.jp/blog/news/JVNVU-90760614.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU90760614/Third Party Advisory
FAQ
What is CVE-2025-41429?
CVE-2025-41429 is a vulnerability with a CVSS score of 4.8 (MEDIUM). a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
How severe is CVE-2025-41429?
CVE-2025-41429 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41429?
Check the references section above for vendor advisories and patch information. Affected products include: Appleple A-Blog Cms.