CVE-2024-23180

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary code by uploading a specially crafted SVG file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*

History

04 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-434

Information

Published : 2024-01-23 10:15

Updated : 2025-06-04 16:15


NVD link : CVE-2024-23180

Mitre link : CVE-2024-23180

CVE.ORG link : CVE-2024-23180


JSON object : View

Products Affected

appleple

  • a-blog_cms
CWE
NVD-CWE-noinfo CWE-434

Unrestricted Upload of File with Dangerous Type