Description
Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.
Remediation
References
https://github.com/xCss/Valine/issues/348
Related Vulnerabilities
CVE-2022-3916 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2018-19361 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-40814 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2013-2165 Vulnerability in maven package org.richfaces.framework:richfaces-impl-jsf2
CVE-2023-28155 Vulnerability in maven package org.webjars.bower:request