Cross Site Scripting Vulnerability in My-Blog by Zhenfeng13
CVE-2025-8740
Key Information:
- Vendor
Zhenfeng13
- Status
- Vendor
- CVE Published:
- 8 August 2025
Badges
What is CVE-2025-8740?
A cross site scripting vulnerability has been identified in the My-Blog application by Zhenfeng13, specifically in the category handler feature located in the /admin/categories/save file. This vulnerability arises due to improper handling of the 'categoryName' argument, which allows an attacker to inject malicious scripts. The exploitation can be executed remotely and poses a significant risk, as it can lead to user data compromise. This vulnerability is publicly disclosed and should be addressed promptly.
Affected Version(s)
My-Blog 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved