CVE-2024-25559: Appleple A-Blog CMS
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
Affected products
- Appleple A-Blog CMS: from 3.1.0, up to and including 3.1.8
Published 2024-02-15. Last modified 2026-06-17.