CVE-2023-29636

C

ross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.

References
Link Resource
https://github.com/ZHENFENG13/My-Blog/issues/131 Exploit Vendor Advisory
https://github.com/ZHENFENG13/My-Blog/issues/131 Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zhenfeng13:my_blog:-:*:*:*:*:*:*:*

History

27 Jan 2026, 15:58

Type Values Removed Values Added
First Time Zhenfeng13 my Blog
Zhenfeng13
CPE cpe:2.3:a:zhenfeng13_my-blog_project:zhenfeng13_my-blog:-:*:*:*:*:*:*:* cpe:2.3:a:zhenfeng13:my_blog:-:*:*:*:*:*:*:*

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://github.com/ZHENFENG13/My-Blog/issues/131 - Exploit, Vendor Advisory () https://github.com/ZHENFENG13/My-Blog/issues/131 - Exploit, Vendor Advisory

Information

Published : 2023-05-01 16:15

Updated : 2026-01-27 15:58


NVD link : CVE-2023-29636

Mitre link : CVE-2023-29636

CVE.ORG link : CVE-2023-29636


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')