First published: Mon Dec 25 2023(Updated: )
openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity Number field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCRX | ||
OpenCRX | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27151 is classified as a medium severity vulnerability due to its potential for HTML injection.
To fix CVE-2023-27151, ensure that input fields in the Search Criteria-Activity Number are properly validated and sanitized to prevent HTML injection.
CVE-2023-27151 impacts users of openCRX version 5.2.0 and earlier due to the vulnerability in the Saved Search Activity.
The impact of CVE-2023-27151 includes the possibility of attackers executing arbitrary HTML or JavaScript in the context of a victim's browser.
Currently, there are no known public exploits specifically targeting CVE-2023-27151.