Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2021-44667 Vulnerability in maven package com.alibaba.nacos:nacos-common
CVE-2020-8141 Vulnerability in maven package org.webjars.npm:dot
CVE-2023-37953 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2019-10745 Vulnerability in npm package assign-deep
CVE-2020-27218 Vulnerability in maven package org.eclipse.jetty:jetty-server