CVE-2022-24374
Summary
| CVE | CVE-2022-24374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-24 15:15:00 UTC |
| Updated | 2022-03-02 16:32:00 UTC |
| Description | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Appleple | A-blog Cms | All | All | All | All |
| Application | Appleple | A-blog Cms | 3.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 複数の脆弱性が発見されました | お知らせ | ブログ | a-blog cms developer | MISC | developer.a-blogcms.jp | |
| JVN#14706307: Multiple vulnerabilities in a-blog cms | MISC | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.