CVE-2024-23180: Input Validation
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary code by uploading a specially crafted SVG file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 3.1.7 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 3.0.29 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.11.58 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.10.50 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23180?
CVE-2024-23180 is considered a medium severity vulnerability due to improper input validation that could allow remote authenticated attackers to exploit the system.
How do I fix CVE-2024-23180?
To resolve CVE-2024-23180, update a-blog cms to version 3.1.7 or later, or 3.0.29 or later for the 3.0.x series.
What versions of a-blog cms are affected by CVE-2024-23180?
CVE-2024-23180 affects a-blog cms versions prior to 3.1.7, 3.0.29, 2.11.58, 2.10.50, and 2.9.0.
Who is vulnerable to CVE-2024-23180?
Organizations using an affected version of a-blog cms are vulnerable to CVE-2024-23180 if they have not applied the necessary updates.
What type of vulnerability is CVE-2024-23180?
CVE-2024-23180 is an improper input validation vulnerability that can be exploited by remote authenticated attackers.