Lucene search

K
cvelistJpcertCVELIST:CVE-2022-24374
HistoryFeb 24, 2022 - 9:50 a.m.

CVE-2022-24374

2022-02-2409:50:32
jpcert
www.cve.org
2
cve-2022-24374
cross-site scripting
remote attacker

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

45.6%

Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916.

CNA Affected

[
  {
    "product": "a-blog cms",
    "vendor": "appleple inc.",
    "versions": [
      {
        "status": "affected",
        "version": "Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1"
      }
    ]
  }
]

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

45.6%

Related for CVELIST:CVE-2022-24374