Description
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
Remediation
References
https://github.com/94fzb/zrlog/issues/39
Related Vulnerabilities
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-manager
CVE-2022-28158 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2023-42278 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector