Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2021-21349 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-27516 Vulnerability in maven package org.webjars.npm:urijs
CVE-2021-4245 Vulnerability in maven package org.webjars.npm:rfc6902
CVE-2023-29924 Vulnerability in maven package tech.powerjob:powerjob
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.components:codemirror