trengh222/hexo-boot-xss1.0

trengh222/hexo-boot-xss1.0

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
The hexo-boot-4.3.0 blog backend has an XSS vulnerability

CVE History

CVEPublishedCVSS v3CVSS v2
2.4 LOW3.3 LOW

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.