Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40814-html-injection-accounts/
Related Vulnerabilities
CVE-2021-32851 Vulnerability in npm package mind-elixir
CVE-2022-45207 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2021-31684 Vulnerability in maven package net.minidev:json-smart
CVE-2021-28161 Vulnerability in npm package @wiptheia/core
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream