Vulnerabilities > Appleple > A Blog CMS > 2.8.68

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2022-24374 Cross-site Scripting vulnerability in Appleple A-Blog CMS
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
appleple CWE-79
6.1