Description
A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-04-08: | Advisory disclosed |
| 2026-04-08: | VulDB entry created |
| 2026-04-08: | VulDB entry last update |
Credits
AhmadMarzook (VulDB User)
References
vuldb.com/vuln/356244 (VDB-356244 | code-projects Easy Blog Site update.php cross site scripting)
vuldb.com/vuln/356244/cti (VDB-356244 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/787045 (Submit #787045 | code-projects Easy Blog Site In PHP 1.0 Cross Site Scripting)
github.com/...) in Easy Blog Site PHP postTitle Parameter.md
code-projects.org/