CVE-2025-5513: quequnlong shiyi-blog add cross site scripting
A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5513?
CVE-2025-5513 is classified as a problematic vulnerability affecting the shiyi-blog software.
What type of vulnerability is CVE-2025-5513?
CVE-2025-5513 is a cross-site scripting (XSS) vulnerability that impacts the comment functionality.
How do I fix CVE-2025-5513?
To fix CVE-2025-5513, update the shiyi-blog software to a version later than 1.2.1.
Which versions of shiyi-blog are affected by CVE-2025-5513?
CVE-2025-5513 affects all versions of shiyi-blog up to and including 1.2.1.
What file is associated with CVE-2025-5513?
CVE-2025-5513 is associated with the file /dev-api/api/comment/add, where the XSS vulnerability can be exploited.