{"id":"CVE-2017-14957","details":"Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated users of the blog.","modified":"2026-07-08T12:06:14.167971Z","published":"2017-10-02T01:29:00.437Z","references":[{"type":"FIX","url":"http://openwall.com/lists/oss-security/2017/10/01/1"},{"type":"FIX","url":"https://github.com/BlogoText/blogotext/issues/318"},{"type":"FIX","url":"https://github.com/BlogoText/blogotext/pull/320/commits/1a283cc8ad2cda37e0a6aff8f4558b98ecbfd9c2"},{"type":"FIX","url":"https://github.com/BlogoText/blogotext/releases/tag/3.7.6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/blogotext/blogotext","events":[{"introduced":"0"},{"last_affected":"fc1b95de2cb553f36950a0bbfd4beb859b2b15bc"},{"fixed":"54819de7b6e8563bc63cd5e95946393b5396995a"}],"database_specific":{"cpe":"cpe:2.3:a:blogotext_project:blogotext:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.7.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.7.5","3.7.4","3.7.3","3.7.2","3.7.1","3.7.0","3.4.8","3.4.7","3.1.0","3.0.4","3.0.0","3.0.0-pre","2.1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14957.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}