Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
| Software | From | Fixed in |
|---|---|---|
| appleple / a-blog_cms | - | 2.8.80.x |
| appleple / a-blog_cms | 2.10.0 | 2.10.58 |
| appleple / a-blog_cms | 2.11.0 | 2.11.70 |
| appleple / a-blog_cms | 2.9.0 | 2.9.46.x |
| appleple / a-blog_cms | 3.0.0 | 3.0.41 |
| appleple / a-blog_cms | 3.1.0 | 3.1.37 |