Description
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2022-1365 Vulnerability in npm package cross-fetch
CVE-2021-21364 Vulnerability in maven package io.swagger:swagger-codegen
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-25979 Vulnerability in npm package apostrophe
CVE-2021-41561 Vulnerability in maven package org.apache.parquet:parquet