PT-2023-22345 · Unknown · Zhenfeng13 My-Blog

Poppingsnack

·

Publicado

2023-05-01

·

Atualizado

2026-01-27

·

CVE-2023-29636

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZHENFENG13 My-Blog (affected versions not specified)
Description A cross site scripting (XSS) issue allows attackers to inject arbitrary web script or HTML via the title field in the "blog management" page due to the default configuration not using MyBlogUtils.cleanString. This enables attackers to execute malicious scripts on the website.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29636

Produtos afetados

Zhenfeng13 My-Blog