PT-2023-22345 · Unknown · Zhenfeng13 My-Blog

Poppingsnack

·

Published

2023-05-01

·

Updated

2026-01-27

·

CVE-2023-29636

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZHENFENG13 My-Blog (affected versions not specified)
Description A cross site scripting (XSS) issue allows attackers to inject arbitrary web script or HTML via the title field in the "blog management" page due to the default configuration not using MyBlogUtils.cleanString. This enables attackers to execute malicious scripts on the website.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-29636

Affected Products

Zhenfeng13 My-Blog