CVE-2024-23348

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 23, 2024
Updated: Jan 29, 2024

Summary

CVE-2024-23348 is an improper input validation vulnerability found in a-blog cms versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver 2.9 and earlier versions that allows a remote authenticated attacker to execute arbitrary JavaScript code by uploading a specially crafted SVG file. This vulnerability affects a-blog cms software and poses a high risk to organizations as it can lead to the execution of malicious code by an attacker with low privileges over the network, resulting in high impact on integrity and confidentiality of data stored in the affected systems.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-23348 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options