Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wqw-fgqf-9mf2

Опубликовано: 19 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.4

Описание

Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

EPSS

Процентиль: 12%
0.00041
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
9 месяцев назад

Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

EPSS

Процентиль: 12%
0.00041
Низкий

4.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79