Description
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Remediation
References
https://github.com/ruibaby/halo/issues/9
Related Vulnerabilities
CVE-2010-2103 Vulnerability in maven package org.apache.axis2:axis2
CVE-2020-36187 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage.js
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-api
CVE-2023-31890 Vulnerability in maven package com.glazedlists:glazedlists