Metrics
Affected Vendors & Products
Mon, 17 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 16 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save of the component Site Settings. The manipulation of the argument Site Title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer. | |
Title | otale Tale Blog Site Settings save saveOptions cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-16T13:31:05.400Z
Updated: 2025-03-17T14:21:41.903Z
Reserved: 2025-03-15T15:03:14.756Z
Link: CVE-2025-2340

Updated: 2025-03-17T14:21:38.685Z

Status : Received
Published: 2025-03-16T14:15:12.597
Modified: 2025-03-16T14:15:12.597
Link: CVE-2025-2340

No data.