Impact
A cross‑site scripting flaw exists in the process that retrieves chats for the shiyi‑blog chat endpoint. The bug allows an attacker to supply malicious content via the chat_msg argument and cause that content to be executed in a victim’s browser. The impact is the injection of arbitrary scripts which can obtain session cookies, alter page content, or abuse the victim’s credentials when the page is viewed. The weakness is tracked under CWE‑79 and its occurrence stems from a lack of proper input validation and output encoding.
Affected Systems
The vulnerability affects the quequnlong shiyi‑blog product, version 1.0.0 through 1.2.1. Discussion references indicate the flaw is located in the SysChatMsgMapper.getChatMsgList function within blog‑web/src/views/chat/index.vue, part of the chat sendMsg endpoint. The affected code path is exposed to any user who can post or read messages in the blog’s chat feature. There are no publicly documented sub‑versions or patch releases listed in the advisory.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as moderate. The EPSS score is very low (< 1 %) and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attacker may launch the attack remotely by sending a crafted chat_msg parameter in a web request. With insufficient server‑side sanitization and no corrective vendor patch in place, the practical threat remains moderate, although the risk could increase if attackers were able to mount broad‑scale assaults on the chat system.
OpenCVE Enrichment