VYPR

Thinkphp Bjyblog

by Thinkphp Bjyblog Project

CVEs (1)

  • CVE-2021-43682MedDec 2, 2021
    risk 0.40cvss 6.1epss 0.01

    thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].