Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Remediation
References
https://github.com/xCss/Valine/issues/127
Related Vulnerabilities
CVE-2020-8141 Vulnerability in maven package org.webjars.npm:dot
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-29002 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2021-27516 Vulnerability in maven package org.webjars.bower:urijs
CVE-2018-14041 Vulnerability in maven package org.webjars.bower:bootstrap