Vulnerability Details CVE-2024-25559
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.9%
CVSS Severity
CVSS v3 Score 4.7
Products affected by CVE-2024-25559
-
cpe:2.3:a:appleple:a-blog_cms:3.1.0
-
cpe:2.3:a:appleple:a-blog_cms:3.1.1
-
cpe:2.3:a:appleple:a-blog_cms:3.1.2
-
cpe:2.3:a:appleple:a-blog_cms:3.1.3
-
cpe:2.3:a:appleple:a-blog_cms:3.1.4
-
cpe:2.3:a:appleple:a-blog_cms:3.1.5
-
cpe:2.3:a:appleple:a-blog_cms:3.1.6
-
cpe:2.3:a:appleple:a-blog_cms:3.1.7
-
cpe:2.3:a:appleple:a-blog_cms:3.1.8