Description
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
Remediation
References
https://github.com/b3log/symphony/issues/860
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-gradle-plugin
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2019-9154 Vulnerability in npm package openpgp
CVE-2022-36099 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5