CVE Details
Basic Information
| Title | quequnlong shiyi-blog add cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-06-03T17:31:04.892Z |
| Last Seen |
Product Information
| Vendor | quequnlong |
|---|---|
| Product | shiyi-blog |
| Version | 1.2.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A cross-site scripting (XSS) vulnerability in the comment functionality of shiyi-blog allows remote attackers to inject malicious scripts. |
|---|---|
| AI Severity | High |
| Vendor | quequnlong |
| Product | shiyi-blog |
| Affected Version | 1.2.0, 1.2.1 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-79, CWE-94 |
| Bulletin Family | |
| Source Data | quequnlong shiyi-blog 1.2.0 quequnlong shiyi-blog 1.2.1 |
Source Information
| Source Data | quequnlong shiyi-blog 1.2.0 quequnlong shiyi-blog 1.2.1 |
|---|---|
| Source Link |
Description
A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score Summary
Base Score: 5.1 (MEDIUM)