Description
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Remediation
References
Related Vulnerabilities
Apache Tomcat Integer Overflow or Wraparound Vulnerability (CVE-2015-8751)
Oracle HTTP Server CVE-2016-3482 Vulnerability (CVE-2016-3482)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-9064)
qdPM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-26165)
WordPress Plugin AdRotate-Ad manager & AdSense Ads SQL Injection (5.8.3.1)