Cross-Site Scripting Vulnerability in a-blog CMS Versions by a-blog
CVE-2024-23183

5.4MEDIUM

What is CVE-2024-23183?

A cross-site scripting vulnerability exists in multiple versions of a-blog CMS, where an authenticated remote attacker can exploit the flaw to execute arbitrary scripts in the context of a victim's browser session. This vulnerability affects the 3.1.x, 3.0.x, 2.11.x, 2.10.x, and earlier versions of the a-blog CMS, making it crucial for users to apply the necessary updates to mitigate potential security risks.

Affected Version(s)

a-blog cms Ver.2.9.0 and earlier

a-blog cms Ver.2.10.x series prior to Ver.2.10.50

a-blog cms Ver.2.11.x series prior to Ver.2.11.58

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.