|
[Japanese]
|
JVNDB-2026-000132
|
a-blog cms vulnerable to path traversal
|
a-blog cms provided by appleple inc. contains the following vulnerability.- Path traversal (CWE-22) - CVE-2026-87727
You are affected by this vulnerability only when "Attaching files to emails addressed to the administrator" is enabled in the form settings.
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 6.5 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
CVSS v4 Severity
Base Metrics: 6.9 (Medium) [IPA Score]
- Access Vector (AV): Network
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): None
Vulnerable System Impact
- Confidentiality Impact (VC): Low
- Integrity Impact (VI): Low
- Availability Impact (VA): None
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
|
|
appleple inc.
- a-blog cms versions 3.2.33 and earlier
|
|
Arbitrary files on the system may be read or deleted by a remote unauthenticated attacker.
|
[Update the Software]
Update the software to the latest version according to the information provided by the developer.
According to the developer, no update will be provided for versions 2.11 or earlier, as support for those versions has already ended. Therefore, users of those versions are recommended to upgrade to version 3.0 or later.
[Apply the Workaround]
The developer recommends applying the workaround until the product is updated.
For more details, refer to the information provided by the developer.
|
appleple inc.
|
- Path Traversal(CWE-22) [IPA Evaluation]
|
- CVE-2026-87727
|
- JVN : JVN#20829034
|
- [2026/09/11]
Web page was published
|