CVE-2023-29636
EUVD-2023-3317701.05.2023, 16:15
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zhenfeng13 | my_blog | - |
𝑥
= Vulnerable software versions