ZeroHour

CVE-2023-29636

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p35
Published
()
Modified
Description

Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.

Vendors
zhenfeng13
Products
my blog
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.