Zomplog Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Zomplog version 3.9. This issue allows authenticated users to inject malicious scripts while creating new pages. Attackers can exploit this by crafting harmful image source attributes that, when triggered, execute arbitrary JavaScript in the context of the victim's browser.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, log into an account on Zomplog 3.9. Once logged in, add a new page and inject a script by setting the image source (src) attribute to a malicious payload in the onerror attribute. After saving the page, the injected script will execute when the page is loaded.

Added: Dec 15, 2025, 9:43 PM
Updated: Dec 15, 2025, 10:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.3
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.