Description
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core
CVE-2020-15779 Vulnerability in npm package socket.io-file
CVE-2021-27644 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server
CVE-2020-7706 Vulnerability in npm package connie-lang
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector