Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40816-html-injection-activity-milestone/
Related Vulnerabilities
CVE-2022-34113 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2021-23425 Vulnerability in npm package trim-off-newlines
CVE-2019-10747 Vulnerability in npm package set-value
CVE-2021-3503 Vulnerability in maven package org.wildfly:wildfly-metrics
CVE-2020-2115 Vulnerability in maven package org.jenkins-ci.plugins:nunit