A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a blog post.
- https://github.com/kevinpdicks/Mezzanine-CMS-6.1.0-XSS
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/kevinpdicks/Mezzanine-CMS-6.1.0-XSS
- https://github.com/nomi-sec/PoC-in-GitHub