Description
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
Remediation
References
https://www.esecforte.com/cve-2023-40817-html-injection-product-configuration/
Related Vulnerabilities
CVE-2020-28469 Vulnerability in npm package glob-parent
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty
CVE-2021-3189 Vulnerability in npm package slashify
CVE-2022-36893 Vulnerability in maven package org.jenkins-ci.plugins:rpmsign-plugin