Description
A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Update
AI Analysis

Impact

A cross‑site scripting flaw exists in the process that retrieves chats for the shiyi‑blog chat endpoint. The bug allows an attacker to supply malicious content via the chat_msg argument and cause that content to be executed in a victim’s browser. The impact is the injection of arbitrary scripts which can obtain session cookies, alter page content, or abuse the victim’s credentials when the page is viewed. The weakness is tracked under CWE‑79 and its occurrence stems from a lack of proper input validation and output encoding.

Affected Systems

The vulnerability affects the quequnlong shiyi‑blog product, version 1.0.0 through 1.2.1. Discussion references indicate the flaw is located in the SysChatMsgMapper.getChatMsgList function within blog‑web/src/views/chat/index.vue, part of the chat sendMsg endpoint. The affected code path is exposed to any user who can post or read messages in the blog’s chat feature. There are no publicly documented sub‑versions or patch releases listed in the advisory.

Risk and Exploitability

The CVSS score of 5.1 classifies the issue as moderate. The EPSS score is very low (< 1 %) and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attacker may launch the attack remotely by sending a crafted chat_msg parameter in a web request. With insufficient server‑side sanitization and no corrective vendor patch in place, the practical threat remains moderate, although the risk could increase if attackers were able to mount broad‑scale assaults on the chat system.

Generated by OpenCVE AI on September 15, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • 1. Update to a patched or newer version of shiyi‑blog that has resolved the XSS flaw, if the vendor publishes an update.
  • 2. If an update cannot be applied immediately, enforce server‑side sanitization of the chat_msg input, removing or escaping any HTML or script tags before storing or rendering it.
  • 3. Deploy a content‑security‑policy header that disallows inline scripts and restricts script sources, thereby limiting the impact of any residual injection.
  • 4. As a temporary measure, disable the chat feature or restrict access to trusted users until the vulnerability is addressed.

Generated by OpenCVE AI on September 15, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
Title quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList cross site scripting
First Time appeared Quequnlong
Quequnlong shiyi-blog
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:quequnlong:shiyi-blog:*:*:*:*:*:*:*:*
Vendors & Products Quequnlong
Quequnlong shiyi-blog
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Quequnlong Shiyi-blog
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:21:10.392Z

Reserved: 2026-09-12T15:48:07.537Z

Link: CVE-2026-90564

cve-icon Vulnrichment

Updated: 2026-09-14T17:21:05.827Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T16:16:51.673

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')