Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2021-27516 Vulnerability in maven package org.webjars.bower:urijs
CVE-2020-7693 Vulnerability in maven package org.webjars.npm:sockjs
CVE-2023-34615 Vulnerability in maven package net.pwall.json:jsonutil
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http2:http2-hpack
CVE-2023-28444 Vulnerability in npm package angular-server-side-configuration