Description
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
Remediation
References
https://github.com/Contrast-Security-OSS/Burptrast/tree/main/docs/CVE-2023-33725
Related Vulnerabilities
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2022-36098 Vulnerability in maven package org.xwiki.platform:xwiki-platform-mentions-ui
CVE-2021-23396 Vulnerability in npm package lutils
CVE-2023-26110 Vulnerability in npm package node-bluetooth
CVE-2020-7622 Vulnerability in maven package io.jooby:jooby-netty