Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2020-7766 Vulnerability in npm package json-ptr
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io
CVE-2022-31159 Vulnerability in maven package com.amazonaws:aws-java-sdk-s3
CVE-2023-48089 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2023-34981 Vulnerability in maven package org.apache.tomcat:tomcat-coyote