Cross-Site Scripting Vulnerability in a-blog CMS by a-blog cms
CVE-2022-24374

6.1MEDIUM

Key Information:

Vendor
CVE Published:
24 February 2022

What is CVE-2022-24374?

The a-blog CMS platforms, including various versions from the 2.8.x to 3.0.x series, are susceptible to a cross-site scripting vulnerability, allowing remote authenticated attackers to inject arbitrary scripts. This vulnerability can be exploited through various unspecified vectors, posing a significant risk to the integrity of the affected systems. It is recommended that users upgrade to the latest version immediately to safeguard against potential exploitation.

Affected Version(s)

a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.