Cross-Site Scripting Vulnerability in a-blog CMS Versions Prior to 3.1.7
CVE-2024-23181

6.1MEDIUM

What is CVE-2024-23181?

A cross-site scripting vulnerability exists in a-blog CMS, allowing a remote attacker to inject arbitrary scripts into the web browser of a logged-in user. Attackers can exploit this vulnerability by crafting malicious payloads that, upon interaction, execute scripts in the context of the user's session. This can lead to unauthorized data access, session hijacking, and other malicious activities, potentially compromising user accounts and sensitive information. Users of affected versions are encouraged to upgrade to the latest releases to mitigate this risk.

Affected Version(s)

a-blog cms Ver.2.9.0 and earlier

a-blog cms Ver.2.10.x series prior to Ver.2.10.50

a-blog cms Ver.2.11.x series prior to Ver.2.11.58

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.