Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Remediation
References
https://github.com/xCss/Valine/issues/127
Related Vulnerabilities
CVE-2015-8315 Vulnerability in maven package org.webjars.npm:ms
CVE-2022-23458 Vulnerability in npm package tui-grid
CVE-2022-39259 Vulnerability in maven package io.github.skylot:jadx-plugins-api
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client
CVE-2023-45857 Vulnerability in maven package org.webjars.bowergithub.axios:axios