Impact
BlogSortServiceImpl.addBlogSort in the Mogu Blog v2 application (up to version 5.2) fails to escape the sortName value that is injected into the info.ftl template. An attacker can supply JavaScript code via sortName and have it executed in the browsers of any user who views the page. This cross‑site scripting flaw can be used to steal session cookies or redirect users to malicious sites. The vulnerability is triggered by a remote request parameter, so no authentication is required to exploit it. The flaw also involves untrusted input being evaluated in a template engine, which aligns with CWE‑79 and CWE‑94.
Affected Systems
moxi624 Mogu Blog v2, versions 5.2 and earlier. The vulnerability resides in the blogSort endpoint that uses the info.ftl template within the website.
Risk and Exploitability
The CVSS score is 5.1 and the EPSS score is < 1%, indicating a low but nonzero probability of exploitation. It is not listed in the CISA KEV catalog. Because the flaw can be triggered remotely by submitting a crafted sortName parameter, the risk of exploitation is moderate for any site exposed to untrusted users. Mitigation involves updating to a newer release or applying input validation to prevent script injection.
OpenCVE Enrichment