Description
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
Remediation
References
https://github.com/b3log/symphony/issues/860
Related Vulnerabilities
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-type-builder
CVE-2021-32660 Vulnerability in npm package techdocs-common
CVE-2022-25895 Vulnerability in npm package lite-dev-server
CVE-2022-4135 Vulnerability in npm package electron
CVE-2021-44667 Vulnerability in maven package com.alibaba.nacos:nacos-common