Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40816-html-injection-activity-milestone/
Related Vulnerabilities
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika
CVE-2020-5259 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox
CVE-2022-45391 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror