Description
A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via unsanitized sortName
Action: Apply Update
AI Analysis

Impact

BlogSortServiceImpl.addBlogSort in the Mogu Blog v2 application (up to version 5.2) fails to escape the sortName value that is injected into the info.ftl template. An attacker can supply JavaScript code via sortName and have it executed in the browsers of any user who views the page. This cross‑site scripting flaw can be used to steal session cookies or redirect users to malicious sites. The vulnerability is triggered by a remote request parameter, so no authentication is required to exploit it. The flaw also involves untrusted input being evaluated in a template engine, which aligns with CWE‑79 and CWE‑94.

Affected Systems

moxi624 Mogu Blog v2, versions 5.2 and earlier. The vulnerability resides in the blogSort endpoint that uses the info.ftl template within the website.

Risk and Exploitability

The CVSS score is 5.1 and the EPSS score is < 1%, indicating a low but nonzero probability of exploitation. It is not listed in the CISA KEV catalog. Because the flaw can be triggered remotely by submitting a crafted sortName parameter, the risk of exploitation is moderate for any site exposed to untrusted users. Mitigation involves updating to a newer release or applying input validation to prevent script injection.

Generated by OpenCVE AI on September 15, 2026 at 16:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a newer release of Mogu Blog v2 that includes the fix.
  • Validate and sanitize the sortName parameter on the server side, allowing only safe characters such as alphanumerics and restricting script tags.
  • If an immediate update is not possible, add a strict Content Security Policy to limit script execution and monitor for suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title moxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort cross site scripting
First Time appeared Moxi624
Moxi624 mogu Blog V2
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:moxi624:mogu_blog_v2:*:*:*:*:*:*:*:*
Vendors & Products Moxi624
Moxi624 mogu Blog V2
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Moxi624 Mogu Blog V2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:43:00.283Z

Reserved: 2026-09-12T16:00:01.163Z

Link: CVE-2026-90568

cve-icon Vulnrichment

Updated: 2026-09-16T19:42:57.389Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T17:16:56.773

Modified: 2026-09-16T20:17:39.480

Link: CVE-2026-90568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')