CVE-2024-28713
Critical · CVSS 9.8Mblog Blog System — Unrestricted File Upload leading to Arbitrary Code Execution (CWE-434)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-434
Description
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.
Search profile — drives PoC discovery
Symbols theme managementfile uploadmblogmtonsthemeManagementuploadThemetheme upload endpoint
Keywords CVE-2024-28713Mblogmblog 3.5.0mtons mblogtheme management file uploadarbitrary code execution unrestricted uploadmblog RCEmblog blog system exploitCWE-434 mblog
Versions: 3.5.0
References
- https://gitee.com/mtons/mblog
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%871.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%872.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%873.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%874.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%875.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/Mblog%20blog%20system%20has%20SSTI%20template%20injection%20vulnerability.md
- http://mblog.com
- https://gitee.com/mtons/mblog
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%871.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%872.png
- https://github.com/JiangXiaoBaiJia/cve/blob/main/%E5%9B%BE%E7%89%873.png
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z