Medium severity4.7NVD Advisory· Published Feb 15, 2024· Updated Jun 17, 2026
CVE-2024-25559
CVE-2024-25559
Description
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- appleple inc./a-blog cmsv5Range: Ver.3.1.0 to Ver.3.1.8
Patches
Vulnerability mechanics
References
2- developer.a-blogcms.jp/blog/news/JVN-48966481.htmlnvdVendor Advisory
- jvn.jp/en/jp/JVN48966481/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.