Vulnerability Details CVE-2024-39203
A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-39203
-
cpe:2.3:a:zblogcn:z-blogphp:1.5
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-2
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-3
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-4
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-5
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-6
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-7
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1525-8
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.0.1626
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.1
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.1.1740
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.2
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.2.1935
-
cpe:2.3:a:zblogcn:z-blogphp:1.5.2.1935(zero)
-
cpe:2.3:a:zblogcn:z-blogphp:1.6.0
-
cpe:2.3:a:zblogcn:z-blogphp:1.6.1
-
cpe:2.3:a:zblogcn:z-blogphp:1.6.1.2100
-
cpe:2.3:a:zblogcn:z-blogphp:1.7.2