CVE-2025-27566 - CVE House
Back to Database
Status published Medium CVE-2025-27566

Path traversal vulnerability exists in a-blog cms versions prior to...

Vulnerability Description

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27566

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

appleple inc.

View all reports →

Affected Software

a-blog cms
Vulnerable Versions:
prior to Ver. 3.1.43 (Ver. 3.1.x series), prior to Ver. 3.0.47 (Ver. 3.0.x series)

Timeline

Official Publish: May 19th, 2025
Last Modified: May 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)