Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40814-html-injection-accounts/
Related Vulnerabilities
CVE-2011-1772 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2012-0392 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2021-32818 Vulnerability in npm package haml-coffee
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage