Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Remediation
References
https://github.com/xCss/Valine/issues/127
Related Vulnerabilities
CVE-2020-36282 Vulnerability in maven package com.rabbitmq.jms:rabbitmq-jms
CVE-2022-45143 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2022-42004 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-7795 Vulnerability in npm package get-npm-package-version