CVEbuzz logo
This website displays data collected from external sources, and is not responsible for any aspect of it. Read more...

Security / vulnerability advisories for B3log Solo 2.9.3

Titles listed in dictionary

CPE for product: cpe:2.3:a:b3log:solo:2.9.3:*:*:*:*:*:*:*

Showing 1-2 of 2
Medium-low damage 4.8
Difficult to exploit
(other affected products) Published: Mon Sep 10 23:29:00 2018 UTC. Last Modified: Fri Nov 9 16:06:00 2018 UTC
CPE matches: cpe:2.3:a:b3log:solo:2.9.3:*:*:*:*:*:*:*

Description

In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N (CVSSv3)

Type of bug(s)

References

Medium-low damage 6.1
Easy to exploit
(other affected products) Published: Thu Jun 20 16:15:00 2019 UTC. Last Modified: Fri Jun 21 12:27:00 2019 UTC
CPE matches: cpe:2.3:a:b3log:solo:2.9.3:*:*:*:*:*:*:*

Description

b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a carefully crafted site name in an admin-authenticated HTTP request.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (CVSSv3)

Type of bug(s)

References