A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 12 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Forestblog Project
Forestblog Project forestblog
CPEs cpe:2.3:a:forestblog_project:forestblog:*:*:*:*:*:*:*:*
Vendors & Products Forestblog Project
Forestblog Project forestblog

Wed, 28 May 2025 17:15:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 03:00:00 +0000


Wed, 02 Apr 2025 02:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Title Sayski ForestBlog search cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-31T17:00:11.982Z

Updated: 2025-03-31T18:21:15.623Z

Reserved: 2025-03-30T17:52:50.487Z

Link: CVE-2025-3004

cve-icon Vulnrichment

Updated: 2025-03-31T18:20:58.335Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-31T17:15:43.757

Modified: 2025-06-12T19:54:39.980

Link: CVE-2025-3004

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-31T17:00:11Z

Links: CVE-2025-3004 - Bugzilla