Description
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
Remediation
References
https://github.com/94fzb/zrlog/issues/39
Related Vulnerabilities
CVE-2022-25171 Vulnerability in npm package p4
CVE-2022-35912 Vulnerability in maven package org.grails:grails-databinding
CVE-2021-43776 Vulnerability in npm package @backstage/plugin-auth-backend
CVE-2022-31069 Vulnerability in npm package @ffdc/nestjs-proxy
CVE-2016-3081 Vulnerability in maven package org.apache.struts:struts2-core