Lucene search

K
cvelistJpcertCVELIST:CVE-2022-23916
HistoryFeb 24, 2022 - 9:50 a.m.

CVE-2022-23916

2022-02-2409:50:30
jpcert
www.cve.org
3
cross-site scripting
a-blog
cms
vulnerability

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

45.6%

Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-24374.

CNA Affected

[
  {
    "product": "a-blog cms",
    "vendor": "appleple inc.",
    "versions": [
      {
        "status": "affected",
        "version": "Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1"
      }
    ]
  }
]

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

45.6%

Related for CVELIST:CVE-2022-23916