Vulnerability Description
Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appleple | A-Blog Cms | >= 2.8.0, < 2.8.64 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN10377257/index.htmlThird Party Advisory
- https://developer.a-blogcms.jp/download/legacy.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN10377257/index.htmlThird Party Advisory
- https://developer.a-blogcms.jp/download/legacy.htmlVendor Advisory
FAQ
What is CVE-2019-6033?
CVE-2019-6033 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script o...
How severe is CVE-2019-6033?
CVE-2019-6033 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6033?
Check the references section above for vendor advisories and patch information. Affected products include: Appleple A-Blog Cms.