Impact
The vulnerability is an XSS flaw located in the highlightKeyword function of the Search component in shiyi‑blog. The function renders the title or summary field without proper sanitization, so an attacker can supply malicious input that is executed as script in the victim’s browser.
Affected Systems
Affected products are quequnlong:shiyi-blog up The flaw resides in the blog‑web component under components/Search. All releases up to 1.2.1 are vulnerable.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The description states the attack can be initiated remotely; exploitation results in client‑side script execution in the context of the web interface.
OpenCVE Enrichment