Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/
Related Vulnerabilities
CVE-2020-7726 Vulnerability in npm package safe-object2
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.web
CVE-2023-31890 Vulnerability in maven package com.glazedlists:glazedlists
CVE-2022-25908 Vulnerability in npm package create-choo-electron
CVE-2016-10707 Vulnerability in maven package org.webjars.bower:jquery