Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
Remediation
References
https://www.esecforte.com/cve-2023-40809-html-injection-search/
Related Vulnerabilities
CVE-2019-9154 Vulnerability in maven package org.webjars.npm:openpgp
CVE-2020-19698 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2017-1000486 Vulnerability in maven package org.primefaces:primefaces
CVE-2019-10807 Vulnerability in npm package blamer
CVE-2021-41184 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui