Sploit.io - Search

Product: a-blog cms, version: Ver. 2.9.52 and earlier (Ver. 2.9.x series)

CVE-2025-36560

Severity: HIGH

Description: Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.

CVSS Score: 8.6

Affected Products:

  • appleple inc. a-blog cms - Versions: Ver. 2.8.85 and earlier (Ver. 2.8.x series)
  • appleple inc. a-blog cms - Versions: Ver. 3.1.43 and earlier (Ver. 3.1.x series)
  • appleple inc. a-blog cms - Versions: Ver. 3.0.47 and earlier (Ver. 3.0.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.11.75 and earlier (Ver. 2.11.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.10.63 and earlier (Ver. 2.10.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.9.52 and earlier (Ver. 2.9.x series)

References:

CVE-2025-41429

Severity: MEDIUM

Description: a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.

CVSS Score: 4.8

Affected Products:

  • appleple inc. a-blog cms - Versions: Ver. 2.8.85 and earlier (Ver. 2.8.x series)
  • appleple inc. a-blog cms - Versions: Ver. 3.1.43 and earlier (Ver. 3.1.x series)
  • appleple inc. a-blog cms - Versions: Ver. 3.0.47 and earlier (Ver. 3.0.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.11.75 and earlier (Ver. 2.11.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.10.63 and earlier (Ver. 2.10.x series)
  • appleple inc. a-blog cms - Versions: Ver. 2.9.52 and earlier (Ver. 2.9.x series)

References: