Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2020-36180 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-16106 Vulnerability in npm package tmock
CVE-2020-22864 Vulnerability in npm package froala-editor
CVE-2018-16487 Vulnerability in npm package lodash._basemerge
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika