Description
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2023-35839 Vulnerability in maven package org.noear:solon.serialization.hessian
CVE-2023-26108 Vulnerability in npm package @nestjs/core
CVE-2020-2303 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2020-2126 Vulnerability in maven package com.dubture.jenkins:digitalocean-plugin