Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40816-html-injection-activity-milestone/
Related Vulnerabilities
CVE-2020-23849 Vulnerability in npm package jsoneditor
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2017-16165 Vulnerability in npm package calmquist.static-server
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.enigma2
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base