PT-2025-35216 · Mtons · Mtons Mblog

Zast.Ai

·

Published

2025-08-29

·

Updated

2025-11-14

·

CVE-2025-9647

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mtons mblog versions up to 3.5.0
Description A weakness exists in mtons mblog due to cross site scripting. The issue affects unknown processing of the file /admin/role/list. Manipulation of the Name argument causes the issue. The exploit has been made publicly available and could be exploited remotely.
Recommendations Versions prior to 3.5.1 are affected. As a temporary workaround, restrict access to the /admin/role/list file to minimize the risk of exploitation. Sanitize the Name argument to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9647

Affected Products

Mtons Mblog