Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the schedule management page.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Appleple
Appleple a-blog Cms |
|
| CPEs | cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Appleple
Appleple a-blog Cms |
Thu, 31 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-31T14:53:49.233Z
Reserved: 2024-04-03T02:24:22.988Z
Link: CVE-2024-31395
Updated: 2024-08-02T01:52:56.829Z
Status : Analyzed
Published: 2024-05-22T05:15:53.120
Modified: 2025-05-12T14:23:17.680
Link: CVE-2024-31395
No data.
OpenCVE Enrichment
No data.