Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2019-9153 Vulnerability in npm package openpgp
CVE-2017-16172 Vulnerability in npm package section2.madisonjbrooks12
CVE-2021-21617 Vulnerability in maven package org.jenkins-ci.plugins: configurationslicing
CVE-2021-25946 Vulnerability in npm package nconf-toml
CVE-2022-24614 Vulnerability in maven package com.drewnoakes:metadata-extractor