PT-2025-34720 · Mtons · Mtons Mblog
Zast.Ai
·
Published
2025-08-25
·
Updated
2025-08-28
·
CVE-2025-9429
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
mtons mblog versions prior to 3.5.1
Description:
A security vulnerability has been detected in mtons mblog. The vulnerability affects unknown code within the
/post/submit file of the Post Handler component. Manipulation of the content/title argument leads to cross-site scripting (XSS). The attack can be initiated remotely, and the exploit has been publicly disclosed.Recommendations:
Update mtons mblog to a version prior to 3.5.1.
As a temporary workaround, restrict or sanitize input to the
content/title argument in the /post/submit file.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mtons Mblog