Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-1146

Disclosure Date: March 19, 2024 (last updated February 26, 2025)
Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
0
Attacker Value
Unknown

CVE-2024-1145

Disclosure Date: March 19, 2024 (last updated February 26, 2025)
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.
0
Attacker Value
Unknown

CVE-2024-1144

Disclosure Date: March 19, 2024 (last updated February 26, 2025)
Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the application's functionalities without the need for credentials.
0