Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16915 Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
Fixes

Solution

Upgrade Alma Blog to version 2.2.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Alma
Alma alma Blog
CPEs cpe:2.3:a:alma:alma_blog:*:*:*:*:*:*:*:*
Vendors & Products Alma
Alma alma Blog

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T18:26:30.513Z

Reserved: 2024-02-01T08:39:01.177Z

Link: CVE-2024-1146

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.513Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-19T12:15:08.443

Modified: 2025-10-15T18:04:10.433

Link: CVE-2024-1146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:40Z