CVE-2026-90564 | quequnlong shiyi-blog 1.0.0-1.2.1 chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList chat_msg cross site scripting (IK5RVL)
A vulnerability was found in quequnlong shiyi-blog 1.0.0-1.2.1 and classified as problematic. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting.
This vulnerability is listed as CVE-2026-90564. The attack may be performed from remote. There is no available exploit.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More