Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
Fixes

Solution

Upgrade Alma Blog to version 2.2.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T18:26:30.513Z

Reserved: 2024-02-01T08:39:01.177Z

Link: CVE-2024-1146

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.513Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-19T12:15:08.443

Modified: 2024-11-21T08:49:54.233

Link: CVE-2024-1146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:40Z