Description
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2015-5211 Vulnerability in maven package org.springframework:spring-web
CVE-2016-4055 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2022-21164 Vulnerability in npm package node-lmdb
CVE-2013-7315 Vulnerability in maven package org.springframework:spring-web