CVE-2023-29636

Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
References
Link Resource
https://github.com/ZHENFENG13/My-Blog/issues/131 Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zhenfeng13_my-blog_project:zhenfeng13_my-blog:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-01 16:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-29636

Mitre link : CVE-2023-29636

CVE.ORG link : CVE-2023-29636


JSON object : View

Products Affected

zhenfeng13_my-blog_project

  • zhenfeng13_my-blog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')