Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-05-22T04:35:09.652Z
Updated: 2024-08-02T01:32:07.430Z
Reserved: 2024-03-27T03:59:36.078Z
Link: CVE-2024-30419
Vulnrichment
Updated: 2024-08-02T01:32:07.430Z
NVD
Status : Awaiting Analysis
Published: 2024-05-22T05:15:52.137
Modified: 2024-07-03T01:54:04.563
Link: CVE-2024-30419
Redhat
No data.