CVE-2022-23810
Summary
| CVE | CVE-2022-23810 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-24 15:15:00 UTC |
| Updated | 2022-03-02 16:28:00 UTC |
| Description | Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Appleple | A-blog Cms | All | All | All | All |
| Application | Appleple | A-blog Cms | 3.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 複数の脆弱性が発見されました | お知らせ | ブログ | a-blog cms developer | MISC | developer.a-blogcms.jp | |
| JVN#14706307: Multiple vulnerabilities in a-blog cms | MISC | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.