Description
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-core
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-common
CVE-2022-37734 Vulnerability in maven package com.graphql-java:graphql-java
CVE-2021-44550 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp