Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-parent
CVE-2020-7627 Vulnerability in npm package node-key-sender
CVE-2019-13236 Vulnerability in maven package org.opencms:opencms-core
CVE-2020-8125 Vulnerability in npm package klona
CVE-2023-37964 Vulnerability in maven package org.jenkins-ci.plugins:elasticbox