Description
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
Remediation
References
https://github.com/94fzb/zrlog/issues/39
Related Vulnerabilities
CVE-2019-15609 Vulnerability in npm package kill-port-process
CVE-2023-29922 Vulnerability in maven package tech.powerjob:powerjob
CVE-2022-24196 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2023-37911 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore