CVE-2022-23916: XSS
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-24374.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23916?
CVE-2022-23916 is a cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.8.75, Ver.2.9.40, Ver.2.10.44, Ver.2.11.42, and Ver.3.0.1.
What is the severity of CVE-2022-23916?
The severity of CVE-2022-23916 is medium with a CVSS score of 6.1.
How can I fix CVE-2022-23916?
To fix CVE-2022-23916, upgrade a-blog cms to at least Ver.2.8.75, Ver.2.9.40, Ver.2.10.44, Ver.2.11.42, or Ver.3.0.1.
What is the CWE of CVE-2022-23916?
The CWE of CVE-2022-23916 is CWE-79 (Cross-site Scripting).
Where can I find more information about CVE-2022-23916?
More information about CVE-2022-23916 can be found at the following references: - [Official advisory from a-blog cms](https://developer.a-blogcms.jp/blog/news/security-202202.html) - [JVN database entry for CVE-2022-23916](https://jvn.jp/en/jp/JVN14706307/index.html)