A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lcg0124
Lcg0124 bootdo |
|
| Vendors & Products |
Lcg0124
Lcg0124 bootdo |
Mon, 19 Jan 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. | |
| Title | lcg0124 BootDo ContentController save cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-01-19T03:32:05.721Z
Updated: 2026-01-19T03:32:05.721Z
Reserved: 2026-01-18T07:18:02.496Z
Link: CVE-2026-1136
No data.
Status : Received
Published: 2026-01-19T04:15:59.303
Modified: 2026-01-19T04:15:59.303
Link: CVE-2026-1136
No data.