Home
MEDIUM: 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NLOW: 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Ver. 2.8.85 and earlier (Ver. 2.8.x series)
affected
Ver. 3.1.43 and earlier (Ver. 3.1.x series)
affected
Ver. 3.0.47 and earlier (Ver. 3.0.x series)
affected
Ver. 2.11.75 and earlier (Ver. 2.11.x series)
affected
Ver. 2.10.63 and earlier (Ver. 2.10.x series)
affected
Ver. 2.9.52 and earlier (Ver. 2.9.x series)
affected
Description
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
Problem types
Improper output neutralization for logs
Product status
References
developer.a-blogcms.jp/blog/news/JVNVU-90760614.html