Description

Multiple cross-site scripting (XSS) vulnerabilities exist in Maian Weblog. User input in comments and other parameters is not properly encoded before rendering.

Impact

Attackers can inject malicious JavaScript into blog comments that executes when other visitors view the page, enabling cookie theft and session hijacking.

Solution

Upgrade to the latest version of Maian Weblog.

References