CVE-2024-23182: Path Traversal
Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to delete arbitrary files on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 3.1.7 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 3.0.29 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.11.58 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.10.50 - Upgrade
Upgrade
a-blog cmsto a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23182?
CVE-2024-23182 has a medium severity level due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2024-23182?
To remediate CVE-2024-23182, upgrade A-blog CMS to versions 3.1.7 or later, 3.0.29 or later, 2.11.58 or later, 2.10.50 or later, or 2.9.1 or later.
Who is affected by CVE-2024-23182?
CVE-2024-23182 affects all installations of A-blog CMS versions prior to the specified patched versions listed in the vulnerability report.
What type of vulnerability is CVE-2024-23182?
CVE-2024-23182 is a relative path traversal vulnerability that can be exploited by remote authenticated attackers.
Can CVE-2024-23182 be exploited remotely?
Yes, CVE-2024-23182 can be exploited remotely by an authenticated user, potentially leading to exposure of sensitive files.