PT-2026-90873 · Moxi624 · Mogu Blog V2
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
moxi624 Mogu Blog v2 versions prior to 5.3
Description
A remote cross site scripting issue exists in the blogSort endpoint. The problem occurs within the
BlogSortServiceImpl.addBlogSort() function located in the mogu web/src/main/resources/templates/info.ftl file. An attacker can exploit this by manipulating the sortName argument. Cross site scripting is a technique where malicious scripts are injected into trusted websites.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
BlogSortServiceImpl.addBlogSort() function or avoid using the sortName argument in the blogSort endpoint.Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mogu Blog V2