0.001 Low
EPSS
Percentile
24.8%
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.
/admin/nodes/nodes/add/blog
github.com/croogo/croogo
github.com/croogo/croogo/commit/cafaaabe2cef3d1d83652370e30563e6ad7c4158
github.com/croogo/croogo/issues/886
nvd.nist.gov/vuln/detail/CVE-2019-7168