Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
Remediation
References
https://www.esecforte.com/cve-2023-40809-html-injection-search/
Related Vulnerabilities
CVE-2020-7606 Vulnerability in npm package docker-compose-remote-api
CVE-2021-43306 Vulnerability in maven package org.webjars.npm:jquery-validation
CVE-2023-26119 Vulnerability in maven package net.sourceforge.htmlunit:htmlunit
CVE-2023-31890 Vulnerability in maven package com.glazedlists:glazedlists
CVE-2022-25646 Vulnerability in npm package x-data-spreadsheet