Moderate severity vulnerability that affects org.b3log:symphony
Moderate severity
GitHub Reviewed
Published
Mar 6, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Mar 6, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
References