CVE 5.1 MEDIUM

lcg0124 BootDo ContentController save cross site scripting_CVE-2026-1136

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

Basic Information

ID CVE-2026-1136
Source VulDB
Published Jan 19, 2026 at 03:32

Affected Product

Vendor lcg0124
Product BootDo
Version e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb
Affected Versions lcg0124 BootDo e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.