Cross-Site Scripting Vulnerability in langhsu Mblog Blog System
CVE-2024-13199
Key Information:
- Vendor
- Langhsu
- Status
- Mblog Blog System
- Vendor
- CVE Published:
- 9 January 2025
Badges
Summary
A cross-site scripting vulnerability has been identified in the langhsu Mblog Blog System version 3.5.0, specifically within the Search Bar component. This flaw arises from improper handling of the 'kw' parameter in the '/search' file, allowing remote attackers to execute arbitrary JavaScript in the context of the affected application. Exploitation of this vulnerability poses significant security risks, including potential theft of sensitive data or session hijacking. Despite early notification, the vendor has not responded to the disclosure, highlighting the importance of prompt action from users to mitigate any risks associated with this vulnerability.
Affected Version(s)
Mblog Blog System 3.5.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved