Cross Site Scripting Vulnerability in lenve VBlog by lenve
CVE-2025-2364
3.5LOW
What is CVE-2025-2364?
A cross site scripting vulnerability exists in lenve VBlog versions up to 1.0.0, specifically in the addNewArticle function of ArticleService.java. This vulnerability allows attackers to manipulate the mdContent/htmlContent argument, which can lead to remote exploitation. The issue has been publicly disclosed, raising concerns about its potential abuse. Despite prior contact with the vendor regarding this vulnerability, there has been no response, leaving users exposed to possible attacks.
