PT-2026-3423 · Bootdo · Bootdo
Tom132432
·
Published
2026-01-19
·
Updated
2026-01-19
·
CVE-2026-1136
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
lcg0124 BootDo versions prior to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb
Description
A weakness exists in lcg0124 BootDo. The
Save function within the /blog/bContent/save file of the ContentController component is susceptible to cross site scripting. Manipulation of the content, author, and title arguments can trigger this issue. Remote exploitation is possible, and the exploit has been publicly released.Recommendations
Versions prior to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb should be updated.
As a temporary workaround, consider restricting access to the
/blog/bContent/save file.
Avoid using the content, author, and title parameters in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bootdo