Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40812-html-injection-accounts-group/
Related Vulnerabilities
CVE-2021-23784 Vulnerability in npm package tempura
CVE-2023-40809 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2022-2191 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2021-41042 Vulnerability in maven package org.eclipse.lyo:lyo-parent
CVE-2022-38750 Vulnerability in maven package org.yaml:snakeyaml