Medium severity6.1GHSA Advisory· Published Feb 25, 2019· Updated Jun 17, 2026
CVE-2019-9142
CVE-2019-9142
Description
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.b3log:symphonyMaven | < 3.4.7 | 3.4.7 |
Affected products
2- Range: < 3.4.7
Patches
Vulnerability mechanics
References
3- github.com/b3log/symphony/issues/860nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-xgjc-49cw-529mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-9142ghsaADVISORY
News mentions
0No linked articles in our index yet.