Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2023-43642 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons
CVE-2021-23346 Vulnerability in npm package html-parse-stringify