OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
References
| Link | Resource |
|---|---|
| https://gist.github.com/kaoniniang2/03658cc78e789b992b378f4951bedfb7 | Third Party Advisory |
| https://gitee.com/yadong.zhang/DBlog/issues/IB6552 | Exploit Vendor Advisory Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-02-10 18:15
Updated : 2025-03-28 16:49
NVD link : CVE-2024-54954
Mitre link : CVE-2024-54954
CVE.ORG link : CVE-2024-54954
JSON object : View
Products Affected
zhyd
- oneblog
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
