CVE-2024-1146
19.03.2024, 12:15
Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
| Vendor | Product | Version |
|---|---|---|
| alma | alma_blog | 𝑥 ≤ 2.1.10 |
𝑥
= Vulnerable software versions