Description
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33177 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString. |
References
| Link | Providers |
|---|---|
| https://github.com/ZHENFENG13/My-Blog/issues/131 |
|
History
Tue, 27 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zhenfeng13
Zhenfeng13 my Blog |
|
| CPEs | cpe:2.3:a:zhenfeng13:my_blog:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Zhenfeng13 My-blog Project
Zhenfeng13 My-blog Project zhenfeng13 My-blog |
Zhenfeng13
Zhenfeng13 my Blog |
Thu, 30 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-30T16:09:33.582Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29636
Updated: 2024-08-02T14:14:39.749Z
Status : Analyzed
Published: 2023-05-01T16:15:11.377
Modified: 2026-01-27T15:58:36.340
Link: CVE-2023-29636
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD