CVE-2023-29636

Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
References
Link Resource
https://github.com/ZHENFENG13/My-Blog/issues/131 Exploit Vendor Advisory
https://github.com/ZHENFENG13/My-Blog/issues/131 Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zhenfeng13_my-blog_project:zhenfeng13_my-blog:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://github.com/ZHENFENG13/My-Blog/issues/131 - Exploit, Vendor Advisory () https://github.com/ZHENFENG13/My-Blog/issues/131 - Exploit, Vendor Advisory

06 May 2023, 03:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References (MISC) https://github.com/ZHENFENG13/My-Blog/issues/131 - (MISC) https://github.com/ZHENFENG13/My-Blog/issues/131 - Exploit, Vendor Advisory
CPE cpe:2.3:a:zhenfeng13_my-blog_project:zhenfeng13_my-blog:-:*:*:*:*:*:*:*
CWE CWE-79

01 May 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-01 16:15

Updated : 2024-11-21 07:57


NVD link : CVE-2023-29636

Mitre link : CVE-2023-29636

CVE.ORG link : CVE-2023-29636


JSON object : View

Products Affected

zhenfeng13_my-blog_project

  • zhenfeng13_my-blog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')