Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40817-html-injection-product-configuration/
Related Vulnerabilities
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2021-21412 Vulnerability in npm package egf
CVE-2020-36640 Vulnerability in maven package org.bonitasoft.connectors:bonita-connector-webservice
CVE-2020-28448 Vulnerability in npm package multi-ini
CVE-2022-24196 Vulnerability in maven package com.itextpdf:itext7-core