CVE-2018-10680
02.05.2018, 19:29
Z-BlogPHP 1.5.2 has a stored Cross Site Scripting Vulnerability exploitable by an administrator who navigates to "Web site settings --> Basic setting --> Website title" and enters an XSS payload via the zb_system/cmd.php ZC_BLOG_NAME parameter. NOTE: the vendor disputes the security relevance, noting it is "just a functional bug.
Vendor | Product | Version |
---|---|---|
zblogcn | z-blogphp | 1.5.2 |
𝑥
= Vulnerable software versions