Description
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
Remediation
References
https://github.com/xCss/Valine/issues/400
Related Vulnerabilities
CVE-2023-42399 Vulnerability in maven package org.webjars.npm:jodit
CVE-2020-26237 Vulnerability in maven package org.webjars.bowergithub.highlightjs:highlight.js
CVE-2019-1010091 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2023-42276 Vulnerability in maven package cn.hutool:hutool-core