A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 10 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Zhenfeng13
Zhenfeng13 my-blog-layui
CPEs cpe:2.3:a:zhenfeng13:my-blog-layui:1.0:*:*:*:*:*:*:*
Vendors & Products Zhenfeng13
Zhenfeng13 my-blog-layui

Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Apr 2025 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.
Title ZHENFENG13/code-projects My-Blog-layui edit cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-04-14T22:00:09.469Z

Updated: 2025-04-15T03:10:56.015Z

Reserved: 2025-04-14T12:54:16.767Z

Link: CVE-2025-3591

cve-icon Vulnrichment

Updated: 2025-04-15T03:10:52.188Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-14T22:15:16.827

Modified: 2025-10-10T17:04:36.430

Link: CVE-2025-3591

cve-icon Redhat

No data.