Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
Remediation
References
https://www.esecforte.com/cve-2023-40809-html-injection-search/
Related Vulnerabilities
CVE-2019-15955 Vulnerability in npm package total.js
CVE-2020-11023 Vulnerability in maven package org.webjars:jquery
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage
CVE-2022-27263 Vulnerability in npm package strapi
CVE-2020-8124 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse