3.5
CVSSv3

CVE-2025-3592

CVSSv4: 5.1 | CVSSv3: 3.5 | CVSSv2: 4 | VMScore: 610 | EPSS: 0.00029 | KEV: Not Included
Published: 14/04/2025 Updated: 15/04/2025

Vulnerability Summary

Cross-Site Scripting in My-Blog-layui 1.0 via Unsanitized Link Edit Parameters

A Cross Site Scripting (XSS) vulnerability exists in My-Blog-layui version 1.0, developed by ZHENFENG13/code-projects. The vulnerability is located in the /admin/v1/link/edit file and potentially impacts multiple parameters. An attacker can remotely initiate the XSS attack, which could allow malicious script injection. The issue has been publicly disclosed, and there is a risk that the vulnerability might be exploited. Despite early notification, the vendor did not respond to the vulnerability report, leaving the security issue unaddressed.