GHSA-5332-wv38-3pxgMediumCVSS 3.5
A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90564
- https://gitee.com/quequnlong/shiyi-blog
- https://gitee.com/quequnlong/shiyi-blog/issues/IK5RVL
- https://vuldb.com/cve/CVE-2026-90564
- https://vuldb.com/submit/912553
- https://vuldb.com/vuln/403149
- https://vuldb.com/vuln/403149/cti
- https://github.com/advisories/GHSA-5332-wv38-3pxg