Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2018-1002200 Vulnerability in maven package org.codehaus.plexus:plexus-archiver
CVE-2023-26122 Vulnerability in npm package safe-eval
CVE-2021-40663 Vulnerability in npm package deep.assign
CVE-2021-39194 Vulnerability in maven package com.charleskorn.kaml:kaml
CVE-2023-49093 Vulnerability in maven package org.htmlunit:htmlunit