Vulnerability CVE-2023-52264


Published: 2023-12-30   Modified: 2023-12-31

Description:
The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled.

 References:
https://zigrin.com/advisories/thirty-bees-reflected-cross-site-scripting-vulnerability/
https://github.com/thirtybees/beesblog/commit/a3aeed8fcf01c8e4112c168cf2ef7d67c8056daf
https://github.com/thirtybees/beesblog/compare/1.6.1...1.6.2

Copyright 2026, cxsecurity.com

 

Back to Top