Medium severity6.1NVD Advisory· Published Oct 2, 2017· Updated May 13, 2026
CVE-2017-14957
CVE-2017-14957
Description
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated users of the blog.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- openwall.com/lists/oss-security/2017/10/01/1nvdMailing ListPatchThird Party Advisory
- github.com/BlogoText/blogotext/issues/318nvdIssue TrackingPatchThird Party Advisory
- github.com/BlogoText/blogotext/pull/320/commits/1a283cc8ad2cda37e0a6aff8f4558b98ecbfd9c2nvdIssue TrackingPatchThird Party Advisory
- github.com/BlogoText/blogotext/releases/tag/3.7.6nvdPatchRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.