CVE-2024-23183

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute an arbitrary script on the logged-in user's web browser.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*

History

29 Jan 2024, 22:55

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://developer.a-blogcms.jp/blog/news/JVN-34565930.html - () https://developer.a-blogcms.jp/blog/news/JVN-34565930.html - Vendor Advisory
References () https://jvn.jp/en/jp/JVN34565930/ - () https://jvn.jp/en/jp/JVN34565930/ - Third Party Advisory
First Time Appleple a-blog Cms
Appleple

23 Jan 2024, 13:43

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de cross-site scripting en las versiones de la serie a-blog cms Ver.3.1.x anteriores a la Ver.3.1.7, versiones de la serie Ver.3.0.x anteriores a la Ver.3.0.29, versiones de la serie Ver.2.11.x anteriores a la Ver. .2.11.58, versiones de la serie Ver.2.10.x anteriores a la Ver.2.10.50 y Ver.2.9.0 y anteriores permiten a un atacante remoto autenticado ejecutar un script arbitrario en el navegador web del usuario que ha iniciado sesión.

23 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 10:15

Updated : 2024-01-29 22:55


NVD link : CVE-2024-23183

Mitre link : CVE-2024-23183

CVE.ORG link : CVE-2024-23183


JSON object : View

Products Affected

appleple

  • a-blog_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')