Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2020-36649 Vulnerability in maven package org.webjars.npm:papaparse
CVE-2020-7687 Vulnerability in npm package fast-http
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-server-webapp
CVE-2022-0686 Vulnerability in npm package url-parse
CVE-2021-21641 Vulnerability in maven package org.jenkins-ci.plugins:promoted-builds