XSS Vulnerability in Blog_mini 1.0 via Comment Reply Author Name

XSS Vulnerability in Blog_mini 1.0 via Comment Reply Author Name

CVE-2019-9765 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.

Learn more about our Web Application Penetration Testing UK.