Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/saysky/ForestBlog/issues/102 | vendor advisory exploit issue tracking |
https://gist.github.com/Catherines77/ac0b554f3d755879eb12bfd69ef585b1 | third party advisory |