Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40814-html-injection-accounts/
Related Vulnerabilities
CVE-2018-19048 Vulnerability in maven package org.webjars.bower:simditor
CVE-2020-28278 Vulnerability in maven package org.webjars.npm:shvl
CVE-2020-27428 Vulnerability in npm package scratch-svg-renderer
CVE-2021-23343 Vulnerability in npm package path-parse
CVE-2021-4264 Vulnerability in maven package org.webjars.bower:dustjs-linkedin