CVE-2024-13199

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Jan 9, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-13199 is a newly disclosed vulnerability affecting the langhsu Mblog Blog System 3.5.0. This issue lies in an unknown functionality of the Search Bar component, specifically the /search file. Malicious actors can exploit this vulnerability by manipulating the kw argument to initiate cross-site scripting attacks. These attacks can be launched remotely, allowing unauthorized code execution. The vulnerability has been made public, increasing the risk of exploitation. Despite early notification, the vendor has yet to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share