Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the schedule management page.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-05-22T04:35:37.216Z
Updated: 2024-10-31T14:53:49.233Z
Reserved: 2024-04-03T02:24:22.988Z
Link: CVE-2024-31395
Vulnrichment
Updated: 2024-08-02T01:52:56.829Z
NVD
Status : Awaiting Analysis
Published: 2024-05-22T05:15:53.120
Modified: 2024-10-31T15:35:33.107
Link: CVE-2024-31395
Redhat
No data.