Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Appleple
Appleple a-blog Cms |
|
| CPEs | cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Appleple
Appleple a-blog Cms |
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T01:32:07.430Z
Reserved: 2024-03-27T03:59:36.078Z
Link: CVE-2024-30419
Updated: 2024-08-02T01:32:07.430Z
Status : Analyzed
Published: 2024-05-22T05:15:52.137
Modified: 2025-05-12T14:23:06.877
Link: CVE-2024-30419
No data.
OpenCVE Enrichment
No data.