developer.a-blogcms.jp
https://developer.a-blogcms.jp/blog/news/JVN-70977403.html CVE-2024-30419
MEDIUM
Record summary
CVE-2024-30419 has a selected CVSS score of 5.4 (medium).
Description
Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2024 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
a-blog_cmsBrowse appleple / a-blog_cmsDefault status: unknown | CVE List | 3.1.0 to < 3.1.12 | affected |
| 3.0.0 to < 3.0.32 | affected | ||
| 2.11.0 to < 2.11.61 | affected | ||
| 2.10.0 to < 2.10.53 | affected | ||
| Through 2.9 | affected | ||
a-blog cmsBrowse appleple inc. / a-blog cms | CVE List | Ver.2.9 and earlier | affected |
a-blog cms Ver.2.10.x seriesBrowse appleple inc. / a-blog cms Ver.2.10.x series | CVE List | prior to Ver.2.10.53 | affected |
a-blog cms Ver.2.11.x seriesBrowse appleple inc. / a-blog cms Ver.2.11.x series | CVE List | prior to Ver.2.11.61 | affected |
a-blog cms Ver.3.0.x seriesBrowse appleple inc. / a-blog cms Ver.3.0.x series | CVE List | prior to Ver.3.0.32 | affected |
a-blog cms Ver.3.1.x seriesBrowse appleple inc. / a-blog cms Ver.3.1.x series | CVE List | prior to Ver.3.1.12 | affected |
References
3jvn.jp
https://jvn.jp/en/jp/JVN70977403 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-30419