A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | ZeroWdd myblog BlogMapper.xml xml injection | |
Weaknesses | CWE-74 CWE-91 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2025-01-08T21:00:11.283Z
Updated: 2025-01-08T21:00:11.283Z
Reserved: 2025-01-08T12:04:56.202Z
Link: CVE-2024-13190
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-08T21:15:12.303
Modified: 2025-01-08T21:15:12.303
Link: CVE-2024-13190
Redhat
No data.