« Volver al listado

CVE-2024-27279

Estado: AnalizadaMedia (6.5)—

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-27279",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-27279",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-12T20:11:57.193866Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "appleple inc.",
          "product": "a-blog cms Ver.3.1.x series",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.3.1.9 and earlier"
            }
          ]
        },
        {
          "vendor": "appleple inc.",
          "product": "a-blog cms Ver.3.0.x series",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.3.0.30 and earlier"
            }
          ]
        },
        {
          "vendor": "appleple inc.",
          "product": "a-blog cms Ver.2.11.x series",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.11.59 and earlier"
            }
          ]
        },
        {
          "vendor": "appleple inc.",
          "product": "a-blog cms Ver.2.10.x series",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.10.51 and earlier"
            }
          ]
        },
        {
          "vendor": "appleple inc.",
          "product": "a-blog cms",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.9 and earlier "
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-03-12T09:15:10.070",
  "references": [
    {
      "url": "https://developer.a-blogcms.jp/blog/news/JVN-48443978.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN48443978/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://developer.a-blogcms.jp/blog/news/JVN-48443978.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN48443978/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de Directory traversal en a-blog cms Serie Ver.3.1.x Ver.3.1.9 y anteriores, Serie Ver.3.0.x Ver.3.0.30 y anteriores, Serie Ver.2.11.x Ver.2.11.59 y anteriores, Serie Ver.2.10.x Ver.2.10.51 y anteriores, y Ver.2.9 y versiones anteriores. Si se explota esta vulnerabilidad, un usuario con privilegios de editor o superiores que pueda iniciar sesión en el producto puede obtener archivos arbitrarios en el servidor, incluidos archivos de contraseñas."
    }
  ],
  "lastModified": "2026-06-17T07:19:33.627",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78FD364E-37B6-47A4-93E3-64196D5484B1",
              "versionEndIncluding": "2.10.51"
            },
            {
              "criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34273351-2450-40F2-B9E9-454C46B6271F",
              "versionEndIncluding": "2.11.59",
              "versionStartIncluding": "2.11.0"
            },
            {
              "criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7864AE5E-5964-4583-AA42-271352F5E4DA",
              "versionEndIncluding": "3.0.30",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF2DC06A-9858-41F5-9E2C-08D85C95101C",
              "versionEndIncluding": "3.1.9",
              "versionStartIncluding": "3.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}