Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40815-html-injection-category/
Related Vulnerabilities
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-beans
CVE-2022-20612 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:sbt
CVE-2021-27884 Vulnerability in npm package yapi-vendor
CVE-2021-36774 Vulnerability in maven package org.apache.kylin:kylin-core-common