Impact
A reflected cross‑site scripting flaw exists in quequnlong’s shiyi‑blog Add Message API component. By sending malicious content in the body.content field, an attacker can inject JavaScript that executes in the browsers of users who to inject and run arbitrary scripts, which could be used to steer user actions, track session information, or modify page content. The flaw affects quequnlong’s shiyi‑blog application versions up to 1.2.1. No newer releases have been documented as affected; therefore any deployment running 1.2.1 or earlier remains vulnerable. The project was notified early but has not yet responded with a fix. The CVSS score of 5.3 classifies the vulnerability as medium. The EPSS score is below 1%, indicating a very low exploitation probability. The attack vector is remote, requiring only the ability to send crafted requests to the Add Message API; the vulnerability is not listed in the CISA KEV catalog. Funds are required to conduct exploit, but the potential impact on confidentiality and integrity of user data remains significant when an exploit hosts.
Affected Systems
The vulnerability affects quequnlong’s shiyi‑blog application, version 1.2.1 and earlier. The affected component is the Add Message API within blog‑admin/src/views/message/message/index.vue. No newer versions have been reported as patched. Deployments running the vulnerable editions are at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as medium. The EPSS score is below 1%, indicating a very low exploitation probability. The attack vector is remote, requiring only the ability to send crafted requests to the Add Message API; the vulnerability is not listed in the CISA KEV catalog. Funds are required to conduct exploit, but the potential impact on confidentiality and integrity of user data remains significant when an exploit hosts.
OpenCVE Enrichment