CVE-2025-2364

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the argument mdContent/htmlContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenve:vblog:-:*:*:*:*:*:*:*

History

14 Oct 2025, 19:38

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en lenve VBlog hasta la versión 1.0.0. Esta vulnerabilidad afecta a la función addNewArticle del archivo blogserver/src/main/java/org/sang/service/ArticleService.java. La manipulación del argumento mdContent/htmlContent provoca ataques de cross site scripting. El ataque puede ejecutarse remotamente. Se ha hecho público el exploit y puede que sea utilizado. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió.
First Time Lenve
Lenve vblog
References () https://magnificent-dill-351.notion.site/Stored-XSS-Vulnerability-in-VBlog-1-0-0-1adc693918ed80d9bd08e03df0ed7a98 - () https://magnificent-dill-351.notion.site/Stored-XSS-Vulnerability-in-VBlog-1-0-0-1adc693918ed80d9bd08e03df0ed7a98 - Broken Link
References () https://vuldb.com/?ctiid.299863 - () https://vuldb.com/?ctiid.299863 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.299863 - () https://vuldb.com/?id.299863 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.514763 - () https://vuldb.com/?submit.514763 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:lenve:vblog:-:*:*:*:*:*:*:*

17 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-17 06:15

Updated : 2025-10-14 19:38


NVD link : CVE-2025-2364

Mitre link : CVE-2025-2364

CVE.ORG link : CVE-2025-2364


JSON object : View

Products Affected

lenve

  • vblog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')