vendor:
zblogphp
by:
zzw
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: zblogphp
Affected Version From: 1.5.1.1740
Affected Version To: 1.5.1.1740
Patch Exists: YES
Related CWE: CVE-2018-7736
CPE: a:zblogcn:zblogphp:1.5.1.1740
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Z-Blog 1.5.1.1740 XSS Vulnerability
This is a XSS vulnerability than can attack the users. The vulnerability exists in the ZC_BLOG_SUBNAME and ZC_UPLOAD_FILETYPE parameters of the zb_system/cmd.php script. An attacker can inject malicious JavaScript code into the parameters and execute it in the user's browser.
Mitigation:
The vendor has released a patch to address this vulnerability.