Description
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
Remediation
References
https://github.com/b3log/symphony/issues/860
Related Vulnerabilities
CVE-2020-15149 Vulnerability in npm package nodebb
CVE-2021-43787 Vulnerability in npm package nodebb
CVE-2022-31198 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable
CVE-2022-25897 Vulnerability in maven package org.eclipse.milo:sdk-server
CVE-2014-0193 Vulnerability in maven package org.onosproject:onos-netconf-provider-device