Description
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
Remediation
References
https://github.com/Contrast-Security-OSS/Burptrast/tree/main/docs/CVE-2023-33725
Related Vulnerabilities
CVE-2020-8203 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2021-28657 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2022-28367 Vulnerability in maven package org.owasp:antisamy
CVE-2021-43776 Vulnerability in npm package @backstage/plugin-auth-backend
CVE-2020-8897 Vulnerability in maven package com.amazonaws:aws-encryption-sdk-java