Description
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
Remediation
References
https://github.com/b3log/symphony/issues/860
Related Vulnerabilities
CVE-2022-43424 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2021-29624 Vulnerability in npm package fastify-csrf
CVE-2023-27564 Vulnerability in npm package n8n
CVE-2019-17579 Vulnerability in maven package org.sonarsource.sonarqube:sonar-web
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs