CVE-2024-25559: Medium severity a-blog CMS vulnerability
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25559?
CVE-2024-25559 has been assessed as a significant vulnerability due to its potential for URL spoofing affecting the a-blog CMS platform.
How do I fix CVE-2024-25559?
To mitigate CVE-2024-25559, it is advised to upgrade a-blog CMS to version 3.1.9 or later, which addresses this vulnerability.
What versions of a-blog CMS are affected by CVE-2024-25559?
CVE-2024-25559 affects a-blog CMS versions from 3.1.0 to 3.1.8 inclusive.
What kind of attack can be executed using CVE-2024-25559?
An attacker can exploit CVE-2024-25559 by sending a specially crafted request that may redirect the administrator to an arbitrary website through the audit log links.
Who is impacted by CVE-2024-25559?
Administrators of a-blog CMS versions 3.1.0 to 3.1.8 are at risk of being impacted by CVE-2024-25559.