Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40815-html-injection-category/
Related Vulnerabilities
CVE-2022-25851 Vulnerability in npm package jpeg-js
CVE-2022-27260 Vulnerability in npm package buttercms
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-csrf-reactive
CVE-2021-25933 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2021-22060 Vulnerability in maven package org.springframework:spring-core