Description
The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by workGroupList text.
Remediation
References
https://github.com/zlgxzswjy/BUI-select-xss
Related Vulnerabilities
CVE-2018-20594 Vulnerability in maven package org.hswebframework.web:hsweb-system-workflow-local
CVE-2022-43433 Vulnerability in maven package io.jenkins.plugins:screenrecorder
CVE-2021-23413 Vulnerability in npm package jszip
CVE-2022-36913 Vulnerability in maven package org.jenkins-ci.plugins:openstack-heat
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions