PT-2023-22348 · Unknown · Zhenfeng13 My-Blog

Poppingsnack

·

Published

2023-05-01

·

Updated

2026-01-27

·

CVE-2023-29639

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZHENFENG13 My-Blog (affected versions not specified)
Description A cross site scripting (XSS) issue allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString. This enables attackers to potentially execute malicious scripts on the victim's browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-29639

Affected Products

Zhenfeng13 My-Blog