Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2022-26969 Vulnerability in npm package directus
CVE-2018-3771 Vulnerability in npm package statics-server
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-core
CVE-2022-36663 Vulnerability in maven package org.gluu:oxauth-common
CVE-2022-24437 Vulnerability in npm package git-pull-or-clone