First published: Sat Nov 18 2023(Updated: )
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.opencrx:opencrx-core-models | <=5.2.0 | |
Opencrx Opencrx | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40810 is a vulnerability in OpenCRX version 5.2.0 that allows HTML injection via the Product Name Field.
CVE-2023-40810 allows an attacker to perform HTML injection via the Product Name Field in OpenCRX version 5.2.0.
OpenCRX version 5.2.0 is affected by CVE-2023-40810.
CVE-2023-40810 has a CWE ID of 79.
Yes, you can find references for CVE-2023-40810 at the following links: [1](https://www.esecforte.com/cve-2023-40810-html-injection-product-creation/), [2](https://nvd.nist.gov/vuln/detail/CVE-2023-40810), [3](https://github.com/advisories/GHSA-gx82-jm5q-gfw2).